Back

CVE-2018-20961

CRITICAL

In the Linux kernel before 4.16.4, a double free vulnerability in the f_midi_set_alt function of drivers/usb/gadget/function/f_midi.c in the f_midi driver may allow attackers to cause a denial of service or possibly have unspecified other impact.

Published: Aug 7, 2019 Modified: Jun 17, 2026
CWE-415

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (4)

Vendor Product Version
linux linux_kernel * ≥ 4.4 < 4.4.190
linux linux_kernel * ≥ 4.5 < 4.9.96
linux linux_kernel * ≥ 4.10 < 4.14.36
linux linux_kernel * ≥ 4.15.0 < 4.16.4

GitHub Security Advisory GHSA-cfwf-8wx8-588c

In the Linux kernel before 4.16.4, a double free vulnerability in the f_midi_set_alt function of...

References (20)

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 6.34%

Top 7% most likely to be exploited

Threat Score 41.1 / 100

Data Sources

NVD EPSS GitHub