Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2016-3672

36
FAUCET Score

CVE-2016-3672 is a Linux kernel vulnerability affecting versions through 4.5.2, including distributions from Canonical and Novell. It allows local users to bypass Address Space Layout Randomization (ASLR) for setuid/setgid programs by disabling stack-consumption resource limits. Rated 7.8 HIGH, this flaw has low attack complexity and can lead to high confidentiality, integrity, and availability impacts. While not actively exploited in the wild (KEV), public exploit code exists, but there is no significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
12.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*
14.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
15.10CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*
12.0CPE matchmatch criteria
cpe:2.3:a:novell:suse_linux_enterprise_software_development_kit:12.0:*:*:*:*:*:*:*
12.0CPE matchmatch criteria
cpe:2.3:o:novell:suse_linux_enterprise_desktop:12.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

7.8HIGH

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.0

Exploit Intelligence

EPSS Score
1.17%
Probability of exploitation in next 30 days
EPSS Percentile
64.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
ExploitDB: EDB-39669 · Apr 6, 2016
This CVE's current EPSS score of 0.0117 is in the 94th percentile among its peer group of 16,974 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (6)

github_advisorypatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-rt-0:3.10.0-862.rt56.804.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-0:3.10.0-862.el7
View patch
redhatno patchvia redhat_api
Product: Red Hat Enterprise MRG 2Fixed in: realtime-kernel
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: kernel
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: kernel

Vendor Advisories (1)

redhatCVE-2016-3672Low

kernel: unlimiting the stack disables ASLR

Apr 6, 2016

References

git.kernel.org / cgit/linux/kernel/git/torvalds/linux.git/commit
hmarco.org / bugs/CVE-2016-3672-Unlimiting-the-stack-not-longer-dis
hmarco.org / bugs/CVE-2016-3672-Unlimiting-the-stack-not-longer-disables-ASLR.html
lists.fedoraproject.org / pipermail/package-announce/2016-April/182524.html
lists.opensuse.org / opensuse-security-announce/2016-06/msg00044.html
lists.opensuse.org / opensuse-security-announce/2016-06/msg00054.html
Third Party Advisory
lists.opensuse.org / opensuse-security-announce/2016-08/msg00000.html
Third Party Advisory
lists.opensuse.org / opensuse-security-announce/2016-08/msg00044.html
lists.opensuse.org / opensuse-security-announce/2016-08/msg00055.html
access.redhat.com / errata/RHSA-2018:0676
access.redhat.com / errata/RHSA-2018:1062
bugzilla.redhat.com / show_bug.cgi
Issue Tracking
seclists.org / fulldisclosure/2016/Apr/26
github.com / torvalds/linux/commit/8b8addf891de8a00e4d39fc32f93f7c5eb8feceb
PatchVendor Advisory
exploit-db.com / exploits/39669
debian.org / security/2016/dsa-3607
securityfocus.com / archive/1/537996/100/0/threaded
securityfocus.com / bid/85884
securitytracker.com / id/1035506
ubuntu.com / usn/USN-2989-1
Third Party Advisory
ubuntu.com / usn/USN-2996-1
Third Party Advisory
ubuntu.com / usn/USN-2997-1
Third Party Advisory
ubuntu.com / usn/USN-2998-1
Third Party Advisory
ubuntu.com / usn/USN-3000-1
Third Party Advisory
ubuntu.com / usn/USN-3001-1
Third Party Advisory
ubuntu.com / usn/USN-3002-1
Third Party Advisory
ubuntu.com / usn/USN-3003-1
Third Party Advisory
ubuntu.com / usn/USN-3004-1
Third Party Advisory