CVE-2016-0728
HIGH EXPLOITEDLinux kernel <4.4.1 - Privilege Escalation/DoS
Title source: llmDescription
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object references in a certain error case, which allows local users to gain privileges or cause a denial of service (integer overflow and use-after-free) via crafted keyctl commands.
Exploits (16)
exploitdb
WORKING POC
by Perception Point Team · clocallinux
https://www.exploit-db.com/exploits/39277
nomisec
WORKING POC
7 stars
by bittorrent3389 · remote
https://github.com/bittorrent3389/cve-2016-0728
nomisec
WORKING POC
5 stars
by neuschaefer · dos
https://github.com/neuschaefer/cve-2016-0728-testbed
nomisec
WRITEUP
by th30d00r · poc
https://github.com/th30d00r/Linux-Vulnerability-CVE-2016-0728-and-Exploit
References (42)
... and 22 more
Scores
CVSS v3
7.8
EPSS
0.5084
EPSS Percentile
97.9%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
VulnCheck KEV
2016-08-04
Status
published
Products (31)
canonical/ubuntu_linux
12.04
canonical/ubuntu_linux
14.04
canonical/ubuntu_linux
15.04
canonical/ubuntu_linux
15.10
debian/debian_linux
8.0
google/android
4.0
google/android
4.0.1
google/android
4.0.2
google/android
4.0.3
google/android
4.0.4
... and 21 more
Published
Feb 08, 2016
Tracked Since
Feb 18, 2026