PT-2016-2922 · Linux+5 · Linux Kernel+5

Rebel

·

Published

2016-12-02

·

Updated

2025-09-29

·

CVE-2016-8655

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 4.8.12
Description The issue exists due to insufficient checking of a resource's state when it can be shared, allowing a local attacker to potentially gain privileges or cause a denial of service (use-after-free) by exploiting the CAP NET RAW capability to change a socket version. This is related to the packet set ring and packet setsockopt functions.
Recommendations For Linux kernel versions prior to 4.8.12, update to version 4.8.12 or later to resolve the issue. As a temporary workaround, consider restricting the use of the CAP NET RAW capability to minimize the risk of exploitation.

Exploit

Fix

DoS

Race Condition

Use After Free

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2016-2436
ALT-PU-2016-2437
BDU:2016-02353
CESA-2017_0386
CVE-2016-8655
DLA-772-1
ELSA-2017-0386
ELSA-2017-0386-1
ELSA-2017-3508
ELSA-2017-3509
MGASA-2016-0415
MGASA-2017-0003
MGASA-2017-0004
OPENSUSE-SU-2016_3050-1
OPENSUSE-SU-2016_3058-1
OPENSUSE-SU-2016_3061-1
OPENSUSE-SU-2016_3077-1
RHSA-2017:0386
RHSA-2017:0387
RHSA-2017:0402
RHSA-2017_0386
RHSA-2017_0387
SUSE-SU-2016:3039-1
SUSE-SU-2016:3049-1
SUSE-SU-2016:3063-1
SUSE-SU-2016:3093-1
SUSE-SU-2016:3094-1
SUSE-SU-2016:3096-1
SUSE-SU-2016:3098-1
SUSE-SU-2016:3100-1
SUSE-SU-2016:3104-1
SUSE-SU-2016:3109-1
SUSE-SU-2016:3111-1
SUSE-SU-2016:3112-1
SUSE-SU-2016:3113-1
SUSE-SU-2016:3116-1
SUSE-SU-2016:3117-1
SUSE-SU-2016:3119-1
SUSE-SU-2016:3169-1
SUSE-SU-2016:3183-1
SUSE-SU-2016:3197-1
SUSE-SU-2016:3205-1
SUSE-SU-2016:3206-1
SUSE-SU-2016:3247-1
SUSE-SU-2016:3249-1
SUSE-SU-2016_3039-1
SUSE-SU-2016_3049-1
SUSE-SU-2016_3063-1
SUSE-SU-2016_3109-1
SUSE-SU-2016_3111-1
SUSE-SU-2016_3112-1
SUSE-SU-2016_3113-1
SUSE-SU-2016_3119-1
SUSE-SU-2016_3197-1
SUSE-SU-2016_3247-1
SUSE-SU-2016_3249-1
SUSE-SU-2017:0407-1
USN-3149-1
USN-3149-2
USN-3150-1
USN-3150-2
USN-3151-1
USN-3151-2
USN-3151-3
USN-3151-4
USN-3152-1
USN-3152-2

Affected Products

Alt Linux
Centos
Linux Kernel
Red Hat
Suse
Ubuntu