CVE-2016-5696 is a medium-severity vulnerability in the Linux kernel (before version 4.7), specifically within the net/ipv4/tcp_input.c component, affecting various Linux-based products including Android and VM servers. This flaw allows remote attackers to hijack TCP sessions through a blind in-window attack by exploiting improper rate determination of challenge ACK segments. The attack complexity is high, and while it doesn't lead to confidentiality or integrity breaches, it can cause partial denial of service. Although there is no evidence of active exploitation (not in KEV or Hot List), a Proof-of-Concept (PoC) code named "Rover" has been publicly discussed on Reddit, and the vulnerability has received significant media attention with four articles.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 7.0CPE matchmatch criteria | cpe:2.3:o:google:android:*:*:*:*:*:*:*:* | ||
3.3CPE matchmatch criteria | cpe:2.3:a:oracle:vm_server:3.3:*:*:*:*:*:*:* | ||
3.4CPE matchmatch criteria | cpe:2.3:a:oracle:vm_server:3.4:*:*:*:*:*:*:* | ||
<= 4.6.6CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.