CVE-2016-8655
HIGH 7.8EPSS 11.1%
Race condition in net/packet/af_packet.c in the Linux kernel through 4.8.12 allows local users to gain privileges or cause a denial of service (use-after-free) by leveraging the CAP_NET_RAW capability to change a socket version, related to the packet_set_ring and packet_setsockopt functions.
- CVSS v3.1
- 7.8 HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C - EPSS
- 11.13% chance of exploitation in the next 30 days, 96th percentile
- Published
- 2016-12-08
- Updated
- 2024-08-06
Proof-of-concept exploits (11)
- KosukeShimofuji/CVE-2016-86550★ · 2016-12-12
- LakshmiDesai/CVE-2016-86555★ · 2016-12-08
- LucidOfficial/Linux-exploit-suggestor0★ · 2022-06-19
- chorankates/Help1★ · 2023-01-07
- externalist/exploit_playground616★ · 2020-10-01
- likekabin/exploit_playground_lists_androidCVE1★ · 2018-07-17
- likescam/exploit_playground_lists_androidCVE1★ · 2018-07-17
- martinmullins/CVE-2016-8655_Android12★ · 2017-07-01
- pradeepavula/Linux-Exploits-LES-0★ · 2024-02-25
- scarvell/cve-2016-86550★ · 2016-12-07
- WhatsWrongAndWhy/CVE-2016-8655
Metasploit modules (1)
ExploitDB entries (3)
- https://www.exploit-db.com/exploits/44696
- https://www.exploit-db.com/exploits/40871
- https://www.exploit-db.com/exploits/47170