Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2016-5696

27
FAUCET Score

CVE-2016-5696 is a medium-severity vulnerability in the Linux kernel (before version 4.7), specifically within the net/ipv4/tcp_input.c component, affecting various Linux-based products including Android and VM servers. This flaw allows remote attackers to hijack TCP sessions through a blind in-window attack by exploiting improper rate determination of challenge ACK segments. The attack complexity is high, and while it doesn't lead to confidentiality or integrity breaches, it can cause partial denial of service. Although there is no evidence of active exploitation (not in KEV or Hot List), a Proof-of-Concept (PoC) code named "Rover" has been publicly discussed on Reddit, and the vulnerability has received significant media attention with four articles.

Impacted Technologies

VendorProductVersion(s)CPE
<= 7.0CPE matchmatch criteria
cpe:2.3:o:google:android:*:*:*:*:*:*:*:*
3.3CPE matchmatch criteria
cpe:2.3:a:oracle:vm_server:3.3:*:*:*:*:*:*:*
3.4CPE matchmatch criteria
cpe:2.3:a:oracle:vm_server:3.4:*:*:*:*:*:*:*
<= 4.6.6CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

4.8MEDIUM

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
LOW
Exploitability Score
2.2
Impact Score
2.5
CvssVersion
3.0

Exploit Intelligence

EPSS Score
15.07%
Probability of exploitation in next 30 days
EPSS Percentile
96.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
This CVE's current EPSS score of 0.1507 is in the 97th percentile among its peer group of 19,953 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (10)

github_advisorypatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: kernel-0:2.6.32-642.4.2.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6.5 Advanced Update SupportFixed in: kernel-0:2.6.32-431.73.2.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6.6 Extended Update SupportFixed in: kernel-0:2.6.32-504.52.1.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6.7 Extended Update SupportFixed in: kernel-0:2.6.32-573.34.1.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-rt-0:3.10.0-327.28.3.rt56.235.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-0:3.10.0-327.28.3.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.1 Extended Update SupportFixed in: kernel-0:3.10.0-229.40.1.ael7b
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise MRG 2Fixed in: kernel-rt-1:3.10.0-327.rt56.195.el6rt
View patch
oraclevendor investigatingvia nvd_reference
View patch

Vendor Advisories (1)

redhatCVE-2016-5696Important

kernel: challenge ACK counter information disclosure.

Jul 12, 2016

References

git.kernel.org / cgit/linux/kernel/git/torvalds/linux.git/commit
Issue TrackingPatch
rhn.redhat.com / errata/RHSA-2016-1631.html
rhn.redhat.com / errata/RHSA-2016-1632.html
rhn.redhat.com / errata/RHSA-2016-1633.html
rhn.redhat.com / errata/RHSA-2016-1657.html
rhn.redhat.com / errata/RHSA-2016-1664.html
rhn.redhat.com / errata/RHSA-2016-1814.html
rhn.redhat.com / errata/RHSA-2016-1815.html
rhn.redhat.com / errata/RHSA-2016-1939.html
bto.bluecoat.com / security-advisory/sa131
bugzilla.redhat.com / show_bug.cgi
Issue Tracking
github.com / Gnoxter/mountain_goat
ExploitThird Party Advisory
github.com / torvalds/linux/commit/75ff39ccc1bd5d3c455b6822ab09e533c551f758
Issue TrackingPatch
kc.mcafee.com / corporate/index
source.android.com / security/bulletin/2016-10-01.html
Third Party Advisory
security.paloaltonetworks.com / CVE-2016-5696
arista.com / en/support/advisories-notices/security-advisories/1461-security-advisory-23
usenix.org / system/files/conference/usenixsecurity16/sec16_paper_cao.pdf
Technical Description
openwall.com / lists/oss-security/2016/07/12/2
Mailing ListThird Party Advisory
oracle.com / technetwork/topics/security/linuxbulletinjul2016-3090544.html
Third Party Advisory
oracle.com / technetwork/topics/security/ovmbulletinjul2016-3090546.html
Vendor Advisory
prnewswire.com / news-releases/mitnick-attack-reappears-at-geekpwn-macau-contest-300270779.html
Technical Description
securityfocus.com / bid/91704
securitytracker.com / id/1036625
ubuntu.com / usn/USN-3070-1
ubuntu.com / usn/USN-3070-2
ubuntu.com / usn/USN-3070-3
ubuntu.com / usn/USN-3070-4
ubuntu.com / usn/USN-3071-1
ubuntu.com / usn/USN-3071-2
ubuntu.com / usn/USN-3072-1
ubuntu.com / usn/USN-3072-2