Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2016-9793

31
FAUCET Score

CVE-2016-9793 is a high-severity vulnerability affecting the Linux kernel before version 4.8.14, specifically within the sock_setsockopt function. It allows local users with CAP_NET_ADMIN capabilities to trigger a denial of service (memory corruption and system crash) or potentially other impacts by manipulating socket buffer sizes. The vulnerability has a CVSS score of 7.8, indicating a high risk due to its low attack complexity and potential for high impact on confidentiality, integrity, and availability. While not listed on the KEV catalog, an exploit (EDB-41995) exists for local privilege escalation, though there is no evidence of active exploitation or significant community discussion.

Impacted Technologies

VendorProductVersion(s)CPE
>= 3.5, < 3.12.69CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 3.13, < 3.16.40CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 3.17, < 3.18.52CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 3.19, < 4.1.50CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.2, < 4.4.38CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.57%
Probability of exploitation in next 30 days
EPSS Percentile
72.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
ExploitDB: EDB-41995 · Mar 22, 2017
This CVE's current EPSS score of 0.0157 is in the 95th percentile among its peer group of 17,061 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (4)

github_advisorypatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-rt-0:3.10.0-514.16.1.rt56.437.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-0:3.10.0-514.16.1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise MRG 2Fixed in: kernel-rt-1:3.10.0-514.rt56.219.el6rt
View patch

Vendor Advisories (1)

redhatCVE-2016-9793Moderate

kernel: Signed overflow for SO_{SND|RCV}BUFFORCE

Dec 2, 2016

References

git.kernel.org / cgit/linux/kernel/git/torvalds/linux.git/commit
PatchVendor Advisory
access.redhat.com / errata/RHSA-2017:0931
Third Party Advisory
access.redhat.com / errata/RHSA-2017:0932
Third Party Advisory
access.redhat.com / errata/RHSA-2017:0933
Third Party Advisory
bugzilla.redhat.com / show_bug.cgi
Issue TrackingThird Party Advisory
github.com / torvalds/linux/commit/b98b0bc8c431e3ceb4b26b0dfc8db509518fb290
PatchVendor Advisory
github.com / xairy/kernel-exploits/tree/master/CVE-2016-9793
Third Party Advisory
source.android.com / security/bulletin/2017-03-01.html
Third Party Advisory
kernel.org / pub/linux/kernel/v4.x/ChangeLog-4.8.14
Release NotesVendor Advisory
openwall.com / lists/oss-security/2016/12/03/1
Mailing ListPatchThird Party Advisory
securityfocus.com / bid/94655
Third Party AdvisoryVDB Entry
securitytracker.com / id/1037968
Third Party AdvisoryVDB Entry