The omninet_open function in drivers/usb/serial/omninet.c in the Linux kernel before 4.10.4 allows local users to cause a denial of service (tty exhaustion) by leveraging reference count mishandling.
https://github.com/torvalds/linux/commit/30572418b445d85fcfe6c8fe84c947d2606767d8
http://www.securityfocus.com/bid/98462
http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.10.4