CVE-2016-4486 is a local information disclosure vulnerability affecting the Linux kernel before version 4.5.5, specifically within the rtnl_fill_link_ifmap function. A low-privileged local attacker can exploit this flaw to read uninitialized kernel stack memory via Netlink messages, potentially exposing sensitive information. The CVSSv3 score is 3.3 (Low), indicating a low attack complexity and impact limited to confidentiality. While there is an ExploitDB entry (EDB-46006), there is no evidence of active exploitation, Metasploit modules, or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11.0CPE matchmatch criteria | cpe:2.3:a:novell:suse_linux_enterprise_software_development_kit:11.0:sp4:*:*:*:*:*:* | ||
12.0CPE matchmatch criteria | cpe:2.3:a:novell:suse_linux_enterprise_software_development_kit:12.0:*:*:*:*:*:*:* | ||
12.0CPE matchmatch criteria | cpe:2.3:a:novell:suse_linux_enterprise_software_development_kit:12.0:sp1:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:o:novell:suse_linux_enterprise_debuginfo:11.0:sp4:*:*:*:*:*:* | ||
12.0CPE matchmatch criteria | cpe:2.3:o:novell:suse_linux_enterprise_desktop:12.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.