SB2016072501 - Memory leak in Airspy USB device driver in Linux kernel
Published: July 5, 2016
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Memory leak in Airspy USB device driver (CVE-ID: CVE-2016-5400)
CWE-ID: CWE-401 - Missing release of memory after effective lifetime
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to consume excessive memory and cause denial of service on the target system.
The vulnerability exists due to a resource error in Airspy USB device driver. A local user can cause a memory leak and consume all available memory resources by creating a specially crafted USB device to emulate multiple SDR devices.
Successful exploitation of this vulnerability may result in denial of service.
Remediation
Cybersecurity Help is not aware of any official remediation provided by the vendor.