CVE-2018-16276 is a local privilege escalation vulnerability affecting the Linux kernel before version 4.17.7, specifically within the yurex USB driver. It stems from incorrect bounds checking during user access read/writes, impacting various distributions including Canonical and Debian Linux. With a CVSS score of 7.8 (High), successful exploitation could lead to a kernel crash or potential privilege escalation, requiring local access and low attack complexity. There is currently no public exploit code available, no evidence of active exploitation, and minimal community discussion or media coverage, suggesting a low immediate threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.6.37, < 3.16.58CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 3.17, < 3.18.116CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 3.19, < 4.4.141CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.5, < 4.9.113CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.10, < 4.14.56CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.