Rapid7’s 2026 Global Cybersecurity Summit is now available on-demand.Watch sessions.
Rapid7

vulnerability

Oracle Linux: (CVE-2016-4482) (Multiple Advisories): Unbreakable Enterprise kernel security update

Severity
2
CVSS
(AV:L/AC:L/Au:N/C:P/I:N/A:N)
Published
May 23, 2016
Added
Feb 7, 2017
Modified
Aug 6, 2024

Description

The proc_connectinfo function in drivers/usb/core/devio.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via a crafted USBDEVFS_CONNECTINFO ioctl call.

Solutions

oracle-linux-upgrade-dtrace-modulesoracle-linux-upgrade-kernel-uekoracle-linux-upgrade-kernel-uek-debugoracle-linux-upgrade-kernel-uek-debug-develoracle-linux-upgrade-kernel-uek-develoracle-linux-upgrade-kernel-uek-docoracle-linux-upgrade-kernel-uek-firmware
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.