CVE-2016-9806: Double Free
A double free vulnerability was found in netlinkdump, which could cause a denial of service or possibly other unspecified impact.
References:
http://seclists.org/oss-sec/2016/q4/577
http://lists.openwall.net/netdev/2016/05/15/69
Upstream patch:
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=92964c79b357efd980812c4de5c1fd2ec8bb5520
Other sources
Race condition in the netlinkdump function in net/netlink/afnetlink.c in the Linux kernel before 4.6.3 allows local users to cause a denial of service (double free) or possibly have unspecified other impact via a crafted application that makes sendmsg system calls, leading to a free operation associated with a new dump that started earlier than anticipated.
— MITRE
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9806?
CVE-2016-9806 has a medium severity rating due to its potential to cause a denial of service.
How do I fix CVE-2016-9806?
To mitigate CVE-2016-9806, it is recommended to update to kernel version 5.10.223-1 or later.
What systems are affected by CVE-2016-9806?
CVE-2016-9806 affects multiple versions of the Linux kernel and Google Android systems.
What kind of impact could CVE-2016-9806 have?
CVE-2016-9806 could lead to a denial of service and potentially other unspecified impacts.
Is CVE-2016-9806 still a concern for current systems?
While CVE-2016-9806 has been patched in newer kernel versions, outdated systems may still be vulnerable.