CVE-2016-8655
Race condition in net/packet/af_packet.c in the Linux kernel through 4.8.12 allows local users to gain privileges or cause a denial of service...
- Published
- Dec 8, 2016
- Updated
- Aug 6, 2024
- Assigning CNA
- redhat
- Evidence observed
- Dec 6, 2016
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HModerate · next 30 days
- Percentile
- 95.8%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
Race condition in net/packet/af_packet.c in the Linux kernel through 4.8.12 allows local users to gain privileges or cause a denial of service (use-after-free) by leveraging the CAP_NET_RAW capability to change a socket version, related to the packet_set_ring and packet_setsockopt functions.
Sources
12- chocoboResearch
Chocobo Root (CVE-2016-8655) Analysis
- kernel-exploitsExploit
Various kernel exploits
- CVE-2016-8655Exploit
Linux kernel local privilege escalation exploit for CVE-2016-8655, targeting AF_PACKET race condition on Ubuntu 16.04 x86_64 to gain root shell via memory manipulation.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.