CVE-2016-3707: High severity linux kernel rt vulnerability

Published Apr 15, 2016
·
Updated

A flaw was found in the kernel-rt in which an attacker could submit a specially crafted ICMP echo request which can trigger a sysrq function based on values in the ICMP packet.

This feature was introduced in the kernel-rt only and is not shipping with standard Red Hat Enterprise Linux kernels.

Remote attacker could exploit this feature using bruteforce to submit arbitrary SysRq commands.

Resources: https://www.kernel.org/pub/linux/kernel/projects/rt/4.4/patch-4.4.7-rt16.patch.gz

Upstream discussion: https://lwn.net/Articles/448790/

CVE request: http://seclists.org/oss-sec/2016/q2/349

Other sources

The icmpchecksysrq function in net/ipv4/icmp.c in the kernel.org projects/rt patches for the Linux kernel, as used in the kernel-rt package before 3.10.0-327.22.1 in Red Hat Enterprise Linux for Real Time 7 and other products, allows remote attackers to execute SysRq commands via crafted ICMP Echo Request packets, as demonstrated by a brute-force attack to discover a cookie, or an attack that occurs after reading the local icmpechosysrq file.

MITRE

Affected Software

4 affected components
Linux Linux Kernel-rt<=3.10.0
redhat Enterprise Linux For Real Time=7
redhat Enterprise Linux For Real Time For Nfv=7
Novell Suse Linux Enterprise Real Time Extension=12.0-sp1

Event History

Apr 15, 2016
Data Sourced
via Red Hat·08:35 AM
DescriptionSeverityAffected Software
Jun 27, 2016
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2016-3707?

CVE-2016-3707 has been classified as a moderate severity vulnerability.

2

How do I fix CVE-2016-3707?

To fix CVE-2016-3707, it is recommended to update the kernel-rt to a version that is higher than 3.10.0.

3

Who is affected by CVE-2016-3707?

CVE-2016-3707 affects systems running kernel-rt versions up to 3.10.0, specifically Red Hat Enterprise Linux for Real Time and SUSE Linux Enterprise Real Time Extension.

4

What type of attack does CVE-2016-3707 enable?

CVE-2016-3707 allows an attacker to submit a crafted ICMP echo request, potentially triggering unintended kernel behavior.

5

Is CVE-2016-3707 present in standard Red Hat kernels?

No, CVE-2016-3707 specifically affects the kernel-rt and is not present in standard Red Hat Enterprise Linux kernels.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203