CVE-2016-6828 is a use-after-free vulnerability in the tcp_check_send_head function of the Linux kernel (before version 4.7.5), allowing local users to cause a denial of service (system crash) via a crafted SACK option. It has a CVSS score of 5.5 (Medium), indicating a local attack vector with low complexity and a high impact on availability. While not actively exploited in the wild, public exploit code exists (EDB-40731), and it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.7.4CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.