CVE-2016-7117 is a critical use-after-free vulnerability in the Linux kernel's __sys_recvmmsg function (net/socket.c), affecting versions prior to 4.5.2, including various Canonical and Debian Linux distributions. This flaw allows remote attackers to execute arbitrary code due to improper handling of the recvmmsg system call during error processing. With a CVSS score of 9.8 (Critical), it presents a high-impact threat (confidentiality, integrity, availability) with a low attack complexity and no user interaction required. While no public exploits (Metasploit, Nuclei, ExploitDB) are currently known, and it is not listed in the KEV catalog, the vulnerability has garnered some community discussion and media coverage, indicating awareness of its potential severity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:* | ||
>= 2.6.33, < 3.2.80CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 3.3, < 3.4.113CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 3.5, < 3.10.102CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 3.11, < 3.12.59CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.