Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2016-1583

30
FAUCET Score

CVE-2016-1583 describes a local privilege escalation and denial-of-service vulnerability in the Linux kernel's ecryptfs_privileged_open function, affecting Canonical, Debian, Linux, and Novell distributions. This flaw allows a local attacker to gain elevated privileges or cause a system crash through crafted mmap calls on /proc pathnames, leading to recursive pagefault handling. Rated with a CVSS score of 7.8 (High), it has low attack complexity and can result in high impact to confidentiality, integrity, and availability. While not listed on the KEV catalog and with no observed active exploitation or significant community discussion, a public exploit (EDB-39992) exists, demonstrating its potential for abuse.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.6.19, < 3.18.54CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 3.19, < 4.4.14CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.5, < 4.6.3CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
11.0CPE matchmatch criteria
cpe:2.3:a:novell:suse_linux_enterprise_software_development_kit:11.0:sp4:*:*:*:*:*:*
12.0CPE matchmatch criteria
cpe:2.3:a:novell:suse_linux_enterprise_software_development_kit:12.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.39%
Probability of exploitation in next 30 days
EPSS Percentile
69.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
ExploitDB: EDB-39992 · Jun 21, 2016
This CVE's current EPSS score of 0.0139 is in the 95th percentile among its peer group of 16,994 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (6)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: kernel-0:2.6.18-416.el5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: kernel-0:2.6.32-642.11.1.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6.7 Extended Update SupportFixed in: kernel-0:2.6.32-573.47.1.el6
View patch
github_advisoryvendor investigatingvia nvd_reference
View patch
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-rt
redhatno patchvia redhat_api
Product: Red Hat Enterprise MRG 2Fixed in: realtime-kernel

Vendor Advisories (1)

redhatCVE-2016-1583Important

kernel: Stack overflow via ecryptfs and /proc/$pid/environ

Jun 10, 2016

References

git.kernel.org / cgit/linux/kernel/git/torvalds/linux.git/commit
Vendor Advisory
git.kernel.org / cgit/linux/kernel/git/torvalds/linux.git/commit
Vendor Advisory
lists.opensuse.org / opensuse-security-announce/2016-06/msg00027.html
Third Party Advisory
lists.opensuse.org / opensuse-security-announce/2016-06/msg00044.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2016-06/msg00052.html
Third Party Advisory
lists.opensuse.org / opensuse-security-announce/2016-06/msg00056.html
Third Party Advisory
lists.opensuse.org / opensuse-security-announce/2016-08/msg00000.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2016-08/msg00003.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2016-08/msg00007.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2016-08/msg00008.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2016-08/msg00009.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2016-08/msg00014.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2016-08/msg00016.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2016-08/msg00018.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2016-08/msg00019.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2016-08/msg00020.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2016-08/msg00021.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2016-08/msg00022.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2016-08/msg00026.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2016-08/msg00044.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2016-08/msg00055.html
Mailing ListThird Party Advisory
packetstormsecurity.com / files/137560/Linux-ecryptfs-Stack-Overflow.html
Third Party AdvisoryVDB Entry
rhn.redhat.com / errata/RHSA-2016-2124.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2016-2766.html
Third Party Advisory
access.redhat.com / errata/RHSA-2017:2760
Third Party Advisory
bugs.chromium.org / p/project-zero/issues/detail
Vendor Advisory
bugzilla.redhat.com / show_bug.cgi
Issue TrackingVDB Entry
github.com / torvalds/linux/commit/2f36db71009304b3f0b95afacd8eba1f9f046b87
Vendor Advisory
github.com / torvalds/linux/commit/f0fe970df3838c202ef6c07a4c2b36838ef0a88b
Third Party Advisory
github.com / torvalds/linux/commit/f5364c150aa645b3d7daa21b5c0b9feaa1c9cd6d
Vendor Advisory
exploit-db.com / exploits/39992
ExploitThird Party AdvisoryVDB Entry
kernel.org / pub/linux/kernel/v4.x/ChangeLog-4.6.3
Release NotesVendor Advisory
debian.org / security/2016/dsa-3607
Third Party Advisory
openwall.com / lists/oss-security/2016/06/10/8
Mailing ListThird Party Advisory
openwall.com / lists/oss-security/2016/06/22/1
Mailing ListThird Party Advisory
securityfocus.com / bid/91157
Third Party AdvisoryVDB Entry
securitytracker.com / id/1036763
Third Party AdvisoryVDB Entry
ubuntu.com / usn/USN-2996-1
Third Party Advisory
ubuntu.com / usn/USN-2997-1
Third Party Advisory
ubuntu.com / usn/USN-2998-1
Third Party Advisory
ubuntu.com / usn/USN-2999-1
Third Party Advisory
ubuntu.com / usn/USN-3000-1
Third Party Advisory
ubuntu.com / usn/USN-3001-1
Third Party Advisory
ubuntu.com / usn/USN-3002-1
Third Party Advisory
ubuntu.com / usn/USN-3003-1
Third Party Advisory
ubuntu.com / usn/USN-3004-1
Third Party Advisory
ubuntu.com / usn/USN-3005-1
Third Party Advisory
ubuntu.com / usn/USN-3006-1
Third Party Advisory
ubuntu.com / usn/USN-3007-1
Third Party Advisory
ubuntu.com / usn/USN-3008-1
Third Party Advisory