CVE-2016-3841 PUBLISHED

The IPv6 stack in the Linux kernel before 4.3.3 mishandles options data, which allows local users to gain privileges or cause a denial of service (use-after-free and system crash) via a crafted sendmsg system call.

EPSS 0.03% · 10.0th percentile

Risk Scores

EPSS Score
0.03%
10.0th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSlinux-lts-wily4.2.0-25.30~14.04.1, 4.2.0-23.28~14.04.1, 4.2.0-22.27~14.04.1
Ubuntu:14.04:LTSlinux-lts-vivid3.19.0-68.76~14.04.1, 3.19.0-66.74~14.04.1, 3.19.0-65.73~14.04.1
Ubuntu:14.04:LTSlinux3.13.0-29.53, 3.13.0-30.54, 3.13.0-30.55
Ubuntu:14.04:LTSlinux-lts-utopic3.16.0-59.79~14.04.1, 3.16.0-57.77~14.04.1, 3.16.0-56.75~14.04.1

Timeline

References

Open in Interactive Console →