Back

CVE-2016-7117

CRITICAL

Use-after-free vulnerability in the __sys_recvmmsg function in net/socket.c in the Linux kernel before 4.5.2 allows remote attackers to execute arbitrary code via vectors involving a recvmmsg system call that is mishandled during error processing.

Published: Oct 10, 2016 Modified: Jun 17, 2026
CWE-19

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (12)

Vendor Product Version
debian debian_linux 7.0
linux linux_kernel * ≥ 2.6.33 < 3.2.80
linux linux_kernel * ≥ 3.3 < 3.4.113
linux linux_kernel * ≥ 3.5 < 3.10.102
linux linux_kernel * ≥ 3.11 < 3.12.59
linux linux_kernel * ≥ 3.13 < 3.14.67
linux linux_kernel * ≥ 3.15 < 3.16.35
linux linux_kernel * ≥ 3.17 < 3.18.37
linux linux_kernel * ≥ 3.19 < 4.1.28
linux linux_kernel * ≥ 4.2.0 < 4.4.8
linux linux_kernel * ≥ 4.5.0 < 4.5.2
canonical ubuntu_linux 16.04

GitHub Security Advisory GHSA-ggx5-r43p-75wm

Use-after-free vulnerability in the __sys_recvmmsg function in net/socket.c in the Linux kernel...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 24.30%

Top 2% most likely to be exploited

Threat Score 46.5 / 100

Data Sources

NVD EPSS GitHub