cve/2016/CVE-2016-7917.md
2024-05-26 14:27:05 +02:00

801 B

CVE-2016-7917

Description

The nfnetlink_rcv_batch function in net/netfilter/nfnetlink.c in the Linux kernel before 4.5 does not check whether a batch message's length field is large enough, which allows local users to obtain sensitive information from kernel memory or cause a denial of service (infinite loop or out-of-bounds read) by leveraging the CAP_NET_ADMIN capability.

POC

Reference

No PoCs from references.

Github