CVE-2016-5696

MEDIUM

Linux kernel <4.7 - RCE

Title source: llm

Description

net/ipv4/tcp_input.c in the Linux kernel before 4.7 does not properly determine the rate of challenge ACK segments, which makes it easier for remote attackers to hijack TCP sessions via a blind in-window attack.

Exploits (5)

nomisec WORKING POC 102 stars
by violentshell · poc
https://github.com/violentshell/rover
nomisec WORKING POC 75 stars
by jduck · poc
https://github.com/jduck/challack
nomisec WORKING POC 40 stars
by Gnoxter · poc
https://github.com/Gnoxter/mountain_goat
nomisec WORKING POC 2 stars
by bplinux · poc
https://github.com/bplinux/chackd
nomisec SCANNER 1 stars
by unkaktus · poc
https://github.com/unkaktus/grill

References (32)

... and 12 more

Scores

CVSS v3 4.8
EPSS 0.3330
EPSS Percentile 96.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L

Classification

CWE
CWE-200
Status draft

Affected Products (4)

google/android < 7.0
oracle/vm_server
oracle/vm_server
linux/linux_kernel < 4.6.6

Timeline

Published Aug 06, 2016
Tracked Since Feb 18, 2026