An issue was discovered in yurex_read in drivers/usb/misc/yurex.c in the Linux kernel before 4.17.7. Local attackers could use user access read/writes with incorrect bounds checking in the yurex USB driver to crash the kernel or potentially escalate privileges.
[
{
"target": {
"function": "yurex_read",
"file": "drivers/usb/misc/yurex.c"
},
"id": "CVE-2018-16276-27165c3f",
"deprecated": false,
"digest": {
"length": 622.0,
"function_hash": "125771205556820398313809484890670548777"
},
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@f1e255d60ae66a9f672ff9a207ee6cd8e33d2679",
"signature_version": "v1"
},
{
"target": {
"file": "drivers/usb/misc/yurex.c"
},
"id": "CVE-2018-16276-58c69d37",
"deprecated": false,
"digest": {
"line_hashes": [
"140360545999078736626882817002803451762",
"231572978339556157751438771493156434299",
"142182977605785106775721546876361691928",
"100133486542169142811310815334819543676",
"217862719992571294548088320581128588141",
"237923349316827071906764938721911581132",
"286214834651534688949044344981859281709",
"262122157929843781030980703597617276628",
"84486303373225353702437371460783847241",
"328339397642860400275928537151728513657",
"184212308127561351535937492309094091552",
"170228131331302210432172929770564901743",
"218111306198750179008417817553981978142",
"51634861079320006753478988630170712366",
"100274303458634514518145331096583212545",
"99673058440852970764439586547003433887",
"133687641839648419925787572288881599258",
"40933211117791338239378717926620104386",
"287492250080137919272544905939768192139",
"283529067146082816262185626222387309458",
"300642685710593676588664767925676132780",
"116250330593876605961268313673593830559",
"12214718060983346730074767024813852977",
"63187098589020733573935926438633442813",
"247523917154823426436798024778572840942"
],
"threshold": 0.9
},
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@f1e255d60ae66a9f672ff9a207ee6cd8e33d2679",
"signature_version": "v1"
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2018-16276.json"