CVE-2016-2550 is a denial-of-service vulnerability affecting the Linux kernel before version 4.5. It allows a local attacker to bypass file-descriptor limits, leading to excessive memory consumption. The vulnerability stems from incorrect tracking of descriptor ownership, a flaw that was an incomplete fix for a previous CVE. With a CVSS score of 5.5 (Medium), this vulnerability requires local access and low attack complexity, resulting in high availability impact. There is no impact on confidentiality or integrity. There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage are minimal, suggesting low current attention to this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.4.8CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.