CVE-2017-16643 describes an out-of-bounds read vulnerability in the Linux kernel's gtco.c driver, affecting versions prior to 4.13.11. A local attacker with low privileges could exploit this by connecting a specially crafted USB device, leading to a denial of service (system crash) or potentially other unspecified impacts. The CVSS score of 6.6 (Medium) indicates a physical attack vector with low complexity, but high impact on confidentiality, integrity, and availability. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion beyond a single mention and one media article, suggesting low current threat activity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.13.11CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.