← All CVEs

CVE-2016-7117

critical · 9.8

Use-after-free vulnerability in the __sys_recvmmsg function in net/socket.c in the Linux kernel before 4.5.2 allows remote attackers to execute arbitrary code via vectors involving a recvmmsg system call that is mishandled during error processing.

9.8
CVSS
23.6%
EPSS (exploit prob.)
98th
EPSS percentile
2016-10-10
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-19

Affected products

VendorProductAffected versions
debiandebian_linux7.0
linuxlinux_kernel>= 2.6.33, < 3.2.80
linuxlinux_kernel>= 3.3, < 3.4.113
linuxlinux_kernel>= 3.5, < 3.10.102
linuxlinux_kernel>= 3.11, < 3.12.59
linuxlinux_kernel>= 3.13, < 3.14.67
linuxlinux_kernel>= 3.15, < 3.16.35
linuxlinux_kernel>= 3.17, < 3.18.37
linuxlinux_kernel>= 3.19, < 4.1.28
linuxlinux_kernel>= 4.2.0, < 4.4.8
linuxlinux_kernel>= 4.5.0, < 4.5.2
canonicalubuntu_linux16.04

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2016-7117