CVE-2016-9793
The sock_setsockopt function in net/core/sock.c in the Linux kernel before 4.8.14 mishandles negative values of sk_sndbuf and sk_rcvbuf, which allows local users to cause a denial of service (memory corruption and system crash) or possibly have unspecified other impact by leveraging the CAP_NET_ADMIN capability for a crafted setsockopt system call with the (1) SO_SNDBUFFORCE or (2) SO_RCVBUFFORCE option.
- Linux Linux Kernel
- < 3.12.69, 3.16.40, 3.18.52, 4.1.50, 4.4.38, 4.8.14
- Fix
- Available
- CVSS 3.1
- 7.8 HIGH
- EPSS
- 1.6% (73th percentile)
- Weakness
- CWE-119
- NVD status
- Modified
- Published
- 2016-12-28
CVE-2016-9793 at NVD
14 known exploits for CVE-2016-9793
Proof-of-concept code and exploit modules indexed by Sploitus
CVE-2016-9793
kernel-exploits
linux-kernel-exploits
kernel-exploits
kernel-exploits
kernel-exploit-factory
Exploit for CVE-2016-2384
Exploit for Use After Free in Linux Linux_Kernel
Exploit for CVE-2016-2384
Linux Kernel SO_SNDBUFFORCE / SO_RCVBUFFORCE Local Privilege Escalation
Linux Kernel 3.11 < 4.8 0 - SO_SNDBUFFORCE & SO_RCVBUFFORCE Local Privilege Escalation Exploi
Linux Kernel 3.11 4.8 0 - SO_SNDBUFFORCE SO_RCVBUFFORCE Local Privilege Escalation
Linux Kernel 3.11 < 4.8 0 - 'SO_SNDBUFFORCE' / 'SO_RCVBUFFORCE' Local Privilege Escalation
Exploit for CVE-2016-2384