CVE-2016-4951: Null Pointer Dereference
Published May 23, 2016
·Updated
Last updated 24 July 2024
Other sources
The tipcnlpubldump function in net/tipc/socket.c in the Linux kernel through 4.6 does not verify socket existence, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a dumpit operation.
Affected Software
8 affected componentsFixes available
Linux Linux kernel>=3.19<4.1.28
Linux Linux kernel>=4.2<4.4.14
Linux Linux kernel>=4.5<4.6.3
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=15.10
Canonical Ubuntu Linux=16.04
Oracle Linux=6
debian/linux
5.10.223-15.10.234-16.1.129-16.1.135-16.12.22-16.12.25-1
Remediation
Patch Available
Event History
May 23, 2016
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Jan 11, 2024
Data Sourced
via Launchpad·10:19 PM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·01:15 AM
RemedyDescriptionSeverityAffected Software
Apr 16, 2025
Data Sourced
via Debian·03:30 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the CVE ID for this vulnerability?
The CVE ID for this vulnerability is CVE-2016-4951.
2
What is the severity of CVE-2016-4951?
The severity of CVE-2016-4951 is not specified.
3
How does CVE-2016-4951 affect the Linux kernel?
CVE-2016-4951 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a dumpit operation.
4
Which versions of the Linux kernel are affected by CVE-2016-4951?
Versions up to 4.6 of the Linux kernel are affected by CVE-2016-4951.
5
How can I fix CVE-2016-4951?
You can fix CVE-2016-4951 by updating the Linux kernel to version 4.7 or later.