CVE-2016-9919 PUBLISHED

The icmp6_send function in net/ipv6/icmp.c in the Linux kernel through 4.8.12 omits a certain check of the dst data structure, which allows remote attackers to cause a denial of service (panic) via a fragmented IPv6 packet.

EPSS 5.46% · 90.1th percentile

Risk Scores

EPSS Score
5.46%
90.1th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSlinux-aws4.4.0-1099.110, 4.4.0-1065.75, 4.4.0-1066.76
Ubuntu:22.04:LTSlinux-intel-iot-realtime0, 5.15.0-1073.75
Ubuntu:20.04:LTSlinux-azure-fde5.4.0-1083.87+cvm1.1, 5.4.0-1085.90+cvm1.1, 5.4.0-1085.90+cvm2.1
Ubuntu:22.04:LTSlinux-realtime0, 5.15.0-1032.35
Ubuntu:16.04:LTSlinux4.4.0-59.80, 4.4.0-51.72, 4.4.0-53.74
Ubuntu:Pro:FIPS:16.04:LTSlinux-fips4.4.0-1041.46, 4.4.0-1034.39, 4.4.0-1013.17
Ubuntu:16.04:LTSlinux-kvm4.4.0-1038.44, 4.4.0-1037.43, 4.4.0-1036.42
Ubuntu:Pro:14.04:LTSlinux-lts-xenial4.4.0-83.106~14.04.1, 0, 4.4.0-13.29~14.04.1
Ubuntu:18.04:LTSlinux-hwe5.3.0-73.69, 4.18.0-18.19~18.04.1, 4.18.0-17.18~18.04.1
Ubuntu:Pro:14.04:LTSlinux-aws4.4.0-1014.14, 4.4.0-1011.11, 4.4.0-1010.10
Ubuntu:22.04:LTSlinux-riscv5.15.0-1006.6, 5.15.0-1005.5, 5.15.0-1004.4
Ubuntu:20.04:LTSlinux-gke5.4.0-1057.60, 5.4.0-1056.59, 5.4.0-1098.105
Ubuntu:18.04:LTSlinux-gcp4.15.0-1009.9, 0, 4.15.0-1001.1
Ubuntu:24.04:LTSlinux-raspi-realtime6.8.0-2019.20, 0
Ubuntu:18.04:LTSlinux-azure5.0.0-1032.34, 5.0.0-1031.33, 5.0.0-1029.31~18.04.1
Ubuntu:20.04:LTSlinux-riscv5.4.0-34.38, 5.4.0-36.41, 5.4.0-37.42
Ubuntu:20.04:LTSlinux-raspi20, 5.3.0-1015.17, 5.3.0-1017.19

Timeline

References

Open in Interactive Console →