An issue was discovered in the Linux kernel before 5.16.12. drivers/net/usb/sr9700.c allows attackers to obtain sensitive information from heap memory via crafted frame lengths from a device.
{
"unresolved_ranges": [
{
"cpe": "cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*",
"extracted_events": [
{
"last_affected": "9.0"
}
],
"source": "CPE_FIELD"
},
{
"cpe": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"fixed": "5.16.12"
}
],
"source": "CPE_FIELD"
},
{
"extracted_events": [
{
"fixed": "5.16.12"
}
],
"source": "DESCRIPTION"
}
]
}