CVE-2016-8655 is a race condition in the Linux kernel's AF_PACKET module (net/packet/af_packet.c) affecting versions through 4.8.12, including Canonical and Ubuntu Linux distributions. This vulnerability allows local users with CAP_NET_RAW capability to achieve privilege escalation or cause a denial of service (use-after-free) by manipulating socket versions. It carries a high CVSS score of 7.8, indicating a low-complexity local attack with high impact on confidentiality, integrity, and availability. While not listed in KEV, multiple public exploits exist, including Metasploit modules and ExploitDB entries, demonstrating its exploitability. The vulnerability has garnered significant community discussion and media coverage, highlighting its potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.2, < 3.2.85CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 3.3, < 3.10.106CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 3.11, < 3.12.69CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 3.13, < 3.16.40CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 3.17, < 3.18.46CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.