CVE-2016-6187 describes an off-by-one vulnerability in the AppArmor component of the Linux kernel versions prior to 4.6.5. This flaw allows a local attacker to gain elevated privileges by manipulating the apparmor_setprocattr function due to improper buffer size validation. With a CVSS score of 7.8 (High), successful exploitation grants full confidentiality, integrity, and availability impact. While not actively exploited in the wild (KEV: No), a Proof-of-Concept exploit (EDB-44301) exists, and the vulnerability has garnered significant community discussion and media coverage, indicating awareness among security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.5, < 4.6.5CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.