CVE-2016-8399Improper Access Control in Kernel

Severity
7.0HIGHNVD
OSV5.5
EPSS
0.2%
top 52.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 12
Latest updateMay 14

Description

An elevation of privilege vulnerability in the kernel networking subsystem could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Moderate because it first requires compromising a privileged process and current compiler optimizations restrict access to the vulnerable code. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-31349935.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.0 | Impact: 5.9

Affected Packages6 packages

NVDlinux/linux_kernel3.194.1.37+2
Debianlinux/linux_kernel< 4.8.15-1+3
Ubuntulinux/linux_kernel< 4.4.0-62.83
CVEListV5google_inc/androidKernel-3.10, Kernel-3.18+1

🔴Vulnerability Details

5
GHSA
GHSA-jjrq-xfh3-2fg8: An elevation of privilege vulnerability in the kernel networking subsystem could enable a local malicious application to execute arbitrary code within2022-05-14
OSV
linux-lts-xenial vulnerabilities2017-02-03
OSV
linux, linux-raspi2, linux-snapdragon vulnerabilities2017-02-03
OSV
CVE-2016-8399: An elevation of privilege vulnerability in the kernel networking subsystem could enable a local malicious application to execute arbitrary code within2017-01-12
Kernel
net: ping: check minimum size on ICMP header length2016-12-05

📋Vendor Advisories

7
Ubuntu
Linux kernel (Raspberry Pi 2) vulnerabilities2017-02-10
Ubuntu
Linux kernel vulnerabilities2017-02-03
Ubuntu
Linux kernel vulnerabilities2017-02-03
Ubuntu
Linux kernel (Xenial HWE) vulnerabilities2017-02-03
Red Hat
kernel: net: Out of bounds stack read in memcpy_fromiovec2016-12-05

💬Community

2
Bugzilla
CVE-2016-8399 kernel: net: Out of bounds stack read in memcpy_fromiovec [fedora-all]2016-12-12
Bugzilla
CVE-2016-8399 kernel: net: Out of bounds stack read in memcpy_fromiovec2016-12-12