CVE-2016-2085 is a timing side-channel vulnerability in the evm_verify_hmac function of the Linux kernel, affecting versions prior to 4.5. This flaw allows local users to more easily forge MAC values due to improper data copying. Rated as Medium severity (CVSS 5.5), it requires local access with low attack complexity and can lead to high integrity impact, though confidentiality and availability are not directly affected. There is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. While it has received some community discussion and media coverage, it is not on the CISA KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.4.8CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.