Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2016-7039


The IP stack in the Linux kernel through 4.8.2 allows remote attackers to cause a denial of service (stack consumption and panic) or possibly have unspecified other impact by triggering use of the GRO path for large crafted packets, as demonstrated by packets that contain only VLAN headers, a related issue to CVE-2016-8666.


Published

2016-10-16T21:59:09.130

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:N/A:C

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: COMPLETE
Exploitability Score

10.0

Impact Score

6.9

Weaknesses
  • Type: Primary
    CWE-399

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System oracle linux 6 Yes
Operating System oracle linux 7 Yes
Operating System oracle vm_server 3.4 Yes
Operating System linux linux_kernel < 4.1.37 Yes
Operating System linux linux_kernel < 4.4.32 Yes
Operating System linux linux_kernel < 4.8.8 Yes

References