#VU14625 Memory corruption in Linux kernel - CVE-2018-16276
Published: September 4, 2018 / Updated: September 5, 2018
Linux kernel
Linux Foundation
Description
The vulnerability allows a local attacker to gain elevated privileges on the target system.
The vulnerability exists due to an out-of-bounds access condition in the yurex_read function, as defined in the drivers/usb/misc/yurex.c source code file. A remote unauthenticated attacker can execute a specially crafted program that submits malicious, trigger memory corruption and gain elevated privileges or cause the service to crash.