CVE-2016-9755 PUBLISHED

The netfilter subsystem in the Linux kernel before 4.9 mishandles IPv6 reassembly, which allows local users to cause a denial of service (integer overflow, out-of-bounds write, and GPF) or possibly have unspecified other impact via a crafted application that makes socket, connect, and writev system calls, related to net/ipv6/netfilter/nf_conntrack_reasm.c and net/ipv6/netfilter/nf_defrag_ipv6_hooks.c.

EPSS 0.05% · 15.7th percentile

Risk Scores

EPSS Score
0.05%
15.7th percentile

Affected Products

VendorProductVersions
Ubuntu:20.04:LTSlinux-azure-fde5.4.0-1063.66+cvm2.2, 5.4.0-1063.66+cvm3.2, 5.4.0-1064.67+cvm1.1
Ubuntu:22.04:LTSlinux-intel-iot-realtime0, 5.15.0-1073.75
Ubuntu:20.04:LTSlinux-raspi20, 5.3.0-1014.16, 5.3.0-1015.17
Ubuntu:22.04:LTSlinux-realtime5.15.0-1032.35, 0
Ubuntu:18.04:LTSlinux-gcp4.15.0-1042.45, 0, 4.15.0-1001.1
Ubuntu:18.04:LTSlinux-hwe5.3.0-68.63, 5.3.0-28.30~18.04.1, 5.3.0-40.32~18.04.1
Ubuntu:22.04:LTSlinux-riscv5.15.0-1017.19, 5.15.0-1016.18, 5.15.0-1015.17
Ubuntu:24.04:LTSlinux-raspi-realtime6.8.0-2019.20, 0
Ubuntu:18.04:LTSlinux-azure4.15.0-1030.31, 0, 4.15.0-1002.2
Ubuntu:20.04:LTSlinux-riscv0, 5.4.0-40.45, 5.4.0-39.44
Ubuntu:16.04:LTSlinux-hwe4.8.0-36.36~16.04.1, 0, 4.10.0-30.34~16.04.1
Ubuntu:20.04:LTSlinux-gke5.4.0-1104.111, 5.4.0-1105.112, 5.4.0-1057.60

Timeline

References

Open in Interactive Console →