Lucene search

K
cveMitreCVE-2016-7039
HistoryOct 16, 2016 - 9:59 p.m.

CVE-2016-7039

2016-10-1621:59:09
CWE-399
mitre
web.nvd.nist.gov
126
linux
kernel
cve-2016-7039
denial of service
nvd
security vulnerability

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

7.8

Confidence

High

EPSS

0.088

Percentile

94.6%

The IP stack in the Linux kernel through 4.8.2 allows remote attackers to cause a denial of service (stack consumption and panic) or possibly have unspecified other impact by triggering use of the GRO path for large crafted packets, as demonstrated by packets that contain only VLAN headers, a related issue to CVE-2016-8666.

Affected configurations

Nvd
Node
oraclelinuxMatch6
OR
oraclelinuxMatch7
OR
oraclevm_serverMatch3.4
Node
linuxlinux_kernelRange4.04.1.37
OR
linuxlinux_kernelRange4.24.4.32
OR
linuxlinux_kernelRange4.54.8.8
VendorProductVersionCPE
oraclelinux6cpe:2.3:o:oracle:linux:6:*:*:*:*:*:*:*
oraclelinux7cpe:2.3:o:oracle:linux:7:*:*:*:*:*:*:*
oraclevm_server3.4cpe:2.3:o:oracle:vm_server:3.4:*:*:*:*:*:*:*
linuxlinux_kernel*cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

7.8

Confidence

High

EPSS

0.088

Percentile

94.6%