CVE-2016-3134 is a critical vulnerability in the netfilter subsystem of the Linux kernel (up to version 4.5.2), also affecting Novell products, where improper validation of offset fields allows local users to achieve privilege escalation or cause a denial of service via an IPT_SO_SET_REPLACE setsockopt call. With a CVSS score of 8.4 (HIGH) and a FAUCET Risk Score of 90/100, this vulnerability presents a significant risk due to its low attack complexity and high potential for impact on confidentiality, integrity, and availability. While not listed on the KEV catalog, an ExploitDB entry (EDB-39545) confirms the availability of exploit code, and the vulnerability has garnered some community discussion and media coverage, indicating awareness among security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11.0CPE matchmatch criteria | cpe:2.3:a:novell:suse_linux_enterprise_software_development_kit:11.0:sp4:*:*:*:*:*:* | ||
12.0CPE matchmatch criteria | cpe:2.3:a:novell:suse_linux_enterprise_software_development_kit:12.0:*:*:*:*:*:*:* | ||
12.0CPE matchmatch criteria | cpe:2.3:a:novell:suse_linux_enterprise_software_development_kit:12.0:sp1:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:o:novell:suse_linux_enterprise_debuginfo:11.0:sp4:*:*:*:*:*:* | ||
12.0CPE matchmatch criteria | cpe:2.3:o:novell:suse_linux_enterprise_desktop:12.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.