Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).
CVE-2016-3134
Severity
8.4HIGH
EPSS
0.0%
top 86.93%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedApr 27
Latest updateMay 14
Description
The netfilter subsystem in the Linux kernel through 4.5.2 does not validate certain offset fields, which allows local users to gain privileges or cause a denial of service (heap memory corruption) via an IPT_SO_SET_REPLACE setsockopt call.
CVSS vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.5 | Impact: 5.9
Affected Packages14 packages
🔴Vulnerability Details
7💥Exploits & PoCs
1📋Vendor Advisories
12Android▶
CVE-2016-3134: Android Security Bulletin 2016-09-01
CVE: CVE-2016-3134
Severity: CRITICAL
References: A-28940694
Upstream
kernel↗2016-09-01