Linux Kernel CVE Statistics
14 Linux Kernel CVEs in October 2016
Full month · Source: NIST NVD
In October 2016, 14 Linux kernel CVEs were published, sourced from the NIST National Vulnerability Database. Of these, 1 was rated Critical, 4 were rated High severity and 9 Medium. No CVEs from this month have been confirmed as actively exploited via the CISA KEV catalog. October's 14 CVEs represent 7% of all 2016 Linux kernel CVEs .
14
Total CVEs
1
Critical
4
High
9
Medium
0
Low
0
KEV Exploited
All CVEs — October 2016
14 CVEs
| CVE ID | Package | Severity | CVSS | Published | Description | |
|---|---|---|---|---|---|---|
| CVE-2016-7117 | linux | Critical | 9.8 | 2016-10-10 | Use-after-free vulnerability in the __sys_recvmmsg function in net/socket.c in the Linux kernel before 4.5.2 allows rem… | |
| CVE-2016-7425 | linux | High | 7.8 | 2016-10-16 | The arcmsr_iop_message_xfer function in drivers/scsi/arcmsr/arcmsr_hba.c in the Linux kernel through 4.8.2 does not res… | |
| CVE-2015-3288 | linux | High | 7.8 | 2016-10-16 | mm/memory.c in the Linux kernel before 4.1.4 mishandles anonymous pages, which allows local users to gain privileges or… | |
| CVE-2016-8666 | linux | High | 7.5 | 2016-10-16 | The IP stack in the Linux kernel before 4.6 allows remote attackers to cause a denial of service (stack consumption and… | |
| CVE-2016-7039 | linux | High | 7.5 | 2016-10-16 | The IP stack in the Linux kernel through 4.8.2 allows remote attackers to cause a denial of service (stack consumption … | |
| CVE-2016-7042 | linux | Medium | 6.2 | 2016-10-16 | The proc_keys_show function in security/keys/proc.c in the Linux kernel through 4.8.2, when the GNU Compiler Collection… | |
| CVE-2016-8658 | linux | Medium | 6.1 | 2016-10-16 | Stack-based buffer overflow in the brcmf_cfg80211_start_ap function in drivers/net/wireless/broadcom/brcm80211/brcmfmac… | |
| CVE-2015-8956 | linux | Medium | 6.1 | 2016-10-10 | The rfcomm_sock_bind function in net/bluetooth/rfcomm/sock.c in the Linux kernel before 4.2 allows local users to obtai… | |
| CVE-2016-6828 | linux | Medium | 5.5 | 2016-10-16 | The tcp_check_send_head function in include/net/tcp.h in the Linux kernel before 4.7.5 does not properly maintain certa… | |
| CVE-2016-6327 | linux | Medium | 5.5 | 2016-10-16 | drivers/infiniband/ulp/srpt/ib_srpt.c in the Linux kernel before 4.5.1 allows local users to cause a denial of service … | |
| CVE-2015-8953 | linux | Medium | 5.5 | 2016-10-16 | fs/overlayfs/copy_up.c in the Linux kernel before 4.2.6 uses an incorrect cleanup code path, which allows local users t… | |
| CVE-2015-8952 | linux | Medium | 5.5 | 2016-10-16 | The mbcache feature in the ext2 and ext4 filesystem implementations in the Linux kernel before 4.6 mishandles xattr blo… | |
| CVE-2016-8660 | linux | Medium | 5.5 | 2016-10-16 | The XFS subsystem in the Linux kernel through 4.8.2 allows local users to cause a denial of service (fdatasync failure … | |
| CVE-2016-7097 | linux | Medium | 4.4 | 2016-10-16 | The filesystem implementation in the Linux kernel through 4.8.2 preserves the setgid bit during a setxattr call, which … |