← All CVEs

CVE-2016-8655

high · 7.8

Race condition in net/packet/af_packet.c in the Linux kernel through 4.8.12 allows local users to gain privileges or cause a denial of service (use-after-free) by leveraging the CAP_NET_RAW capability to change a socket version, related to the packet_set_ring and packet_setsockopt functions.

7.8
CVSS
11.1%
EPSS (exploit prob.)
96th
EPSS percentile
2016-12-08
Published

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-362CWE-416

Affected products

VendorProductAffected versions
linuxlinux_kernel>= 3.2, < 3.2.85
linuxlinux_kernel>= 3.3, < 3.10.106
linuxlinux_kernel>= 3.11, < 3.12.69
linuxlinux_kernel>= 3.13, < 3.16.40
linuxlinux_kernel>= 3.17, < 3.18.46
linuxlinux_kernel>= 3.19, < 4.1.37
linuxlinux_kernel>= 4.2, < 4.4.38
linuxlinux_kernel>= 4.5, < 4.8.14
canonicalubuntu_linux12.04
canonicalubuntu_linux14.04
canonicalubuntu_linux16.04
canonicalubuntu_linux16.10

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2016-8655