CVE-2016-4998 is an out-of-bounds read vulnerability in the Linux kernel's netfilter subsystem, specifically affecting the IPT_SO_SET_REPLACE setsockopt implementation. This flaw impacts various Linux distributions, including Canonical, Oracle, and generic Linux kernels before version 4.6. A local attacker with in-container root access can trigger a denial of service or potentially extract sensitive information from kernel memory by providing a malformed offset. The vulnerability carries a CVSS score of 7.1 (HIGH), indicating a high severity due to its low attack complexity and potential for both confidentiality and availability impacts. While requiring local access, the exploit does not necessitate user interaction. Although not listed on the CISA KEV catalog, a Metasploit module exists for privilege escalation, suggesting exploitability. Community discussion is minimal, with only one mention, and there is no media coverage, indicating a relatively low public profile despite the availability of exploit code.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.5.5CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
7CPE matchmatch criteria | cpe:2.3:o:oracle:linux:7:*:*:*:*:*:*:* | ||
12.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:* | ||
14.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:* | ||
15.10CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.