sound/core/seqdevice.c in the Linux kernel before 4.13.4 allows local users to cause a denial of service (sndrawmididevseq_free use-after-free and system crash) or possibly have unspecified other impact via a crafted USB device.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-16528.json"
[
{
"id": "CVE-2017-16528-d33366fd",
"digest": {
"threshold": 0.9,
"line_hashes": [
"321229081922187099975661487901327602359",
"218523580830630026322326190918768185131",
"328373085419623170822507590398603108081",
"314741133268224150090288688893405793484",
"313211719713004530902827557821803204223",
"206717223730633311081442334823839291980",
"244595708087084772983278690720421743131",
"216767052063958892691746303651311916096"
]
},
"signature_type": "Line",
"target": {
"file": "sound/core/seq_device.c"
},
"signature_version": "v1",
"source": "https://github.com/torvalds/linux/commit/fc27fe7e8deef2f37cba3f2be2d52b6ca5eb9d57",
"deprecated": false
}
]