Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2016-8399

19
FAUCET Score

CVE-2016-8399 is an elevation of privilege vulnerability affecting the Android kernel networking subsystem (versions 3.10 and 3.18). A local malicious application could exploit this to execute arbitrary code within the kernel context. Rated as High severity (CVSS 7.0), successful exploitation requires first compromising a privileged process and is made more difficult by compiler optimizations restricting access to the vulnerable code. There is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), nor is there evidence of active exploitation or significant community discussion.

Impacted Technologies

VendorProductVersion(s)CPE
>= 3.19, < 4.1.37CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.2, < 4.4.38CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.5, < 4.8.14CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.0HIGH

CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.0
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
2.34%
Probability of exploitation in next 30 days
EPSS Percentile
81.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0234 is in the 93rd percentile among its peer group of 386 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.0 Bluesky, 0.1 Mastodon, and 0.0 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (5)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: kernel-0:2.6.32-696.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6.7 Extended Update SupportFixed in: kernel-0:2.6.32-573.41.1.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-rt-0:3.10.0-693.5.2.rt56.626.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-0:3.10.0-693.5.2.el7
View patch
googlevendor investigatingvia nvd_reference
View patch

Vendor Advisories (1)

redhatCVE-2016-8399Moderate

kernel: net: Out of bounds stack read in memcpy_fromiovec

Dec 5, 2016

References

rhn.redhat.com / errata/RHSA-2017-0817.html
Third Party Advisory
access.redhat.com / errata/RHSA-2017:0869
Third Party Advisory
access.redhat.com / errata/RHSA-2017:2930
Third Party Advisory
access.redhat.com / errata/RHSA-2017:2931
Third Party Advisory
source.android.com / security/bulletin/2016-12-01.html
Vendor Advisory
support.f5.com / csp/article/K23030550
Third Party Advisory
securityfocus.com / bid/94708
Third Party AdvisoryVDB Entry