Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2016-6516

23
FAUCET Score

CVE-2016-6516 describes a race condition, specifically a "double fetch" vulnerability, within the ioctl_file_dedupe_range function in the Linux kernel through version 4.7. This flaw allows a local attacker to trigger a heap-based buffer overflow, leading to a denial of service or potentially privilege escalation. The vulnerability is rated as High severity with a CVSS score of 7.4, indicating that while local access and high attack complexity are required, the potential impact on confidentiality, integrity, and availability is significant. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
<= 4.7CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

7.4HIGH

CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.4
Impact Score
5.9
CvssVersion
3.0

Exploit Intelligence

EPSS Score
0.95%
Probability of exploitation in next 30 days
EPSS Percentile
57.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
This CVE's current EPSS score of 0.0095 is in the 93rd percentile among its peer group of 156 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

github_advisorypatch availablevia nvd_reference
View patch

Vendor Advisories (1)

redhatCVE-2016-6516Important

kernel: vfs: ioctl: double fetch leading to heap overflow

Jul 31, 2016

References

git.kernel.org / cgit/linux/kernel/git/torvalds/linux.git/commit
Patch
bugzilla.redhat.com / show_bug.cgi
Issue TrackingThird Party AdvisoryVDB Entry
github.com / torvalds/linux/commit/10eec60ce79187686e052092e5383c99b4420a20
Patch
openwall.com / lists/oss-security/2016/07/31/6
Release Notes
securityfocus.com / bid/92259