Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2017-16528

22
FAUCET Score

CVE-2017-16528 describes a use-after-free vulnerability in the Linux kernel's sound subsystem (sound/core/seq_device.c) affecting versions before 4.13.4, including Canonical and Ubuntu Linux. This flaw, triggerable by a local user with a specially crafted USB device, could lead to a denial of service (system crash) or potentially other unspecified impacts. Rated Medium severity (CVSS 6.6), it requires physical access (AV:P) and low privileges (PR:L) for exploitation, with high impact on confidentiality, integrity, and availability. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 3.19, < 4.1.47CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.2, < 4.4.99CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.5, < 4.9.63CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.10, < 4.13.4CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
14.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.6MEDIUM

CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
PHYSICAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
0.7
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.36%
Probability of exploitation in next 30 days
EPSS Percentile
29.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0037 is in the 43rd percentile among its peer group of 170 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (6)

github_advisorypatch availablevia nvd_reference
View patch
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: kernel
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-alt
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-rt
redhatno patchvia redhat_api
Product: Red Hat Enterprise MRG 2Fixed in: realtime-kernel

Vendor Advisories (1)

redhatCVE-2017-16528Moderate

kernel: use-after-free in snd_rawmidi_dev_seq_free

Sep 12, 2017

References

github.com / torvalds/linux/commit/fc27fe7e8deef2f37cba3f2be2d52b6ca5eb9d57
PatchThird Party Advisory
groups.google.com / d/msg/syzkaller/kuZzDHGkQu8/5du20rZEAAAJ
Third Party Advisory
usn.ubuntu.com / 3619-1
Third Party Advisory
usn.ubuntu.com / 3619-2
Third Party Advisory