CVE-2016-7039

HIGH

Linux Kernel < 4.1.37 - Denial of Service via GRO Path Stack Consumption

Title source: llm
STIX 2.1

Description

The IP stack in the Linux kernel through 4.8.2 allows remote attackers to cause a denial of service (stack consumption and panic) or possibly have unspecified other impact by triggering use of the GRO path for large crafted packets, as demonstrated by packets that contain only VLAN headers, a related issue to CVE-2016-8666.

References (11)

Core 11
Core References
Third Party Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2016-2107.html
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:0372
Third Party Advisory x_refsource_confirm
https://bto.bluecoat.com/security-advisory/sa134
Mailing List, Patch, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2016/10/10/15
Issue Tracking, Third Party Advisory x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=1375944
Issue Tracking, Patch x_refsource_confirm
https://patchwork.ozlabs.org/patch/680412/
Third Party Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2016-2047.html
Third Party Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2016-2110.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/93476

Scores

CVSS v3 7.5
EPSS 0.0761
EPSS Percentile 94.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-399
Status published
Products (4)
linux/linux_kernel 4.0 - 4.1.37
oracle/linux 6
oracle/linux 7
oracle/vm_server 3.4
Published Oct 16, 2016
Tracked Since Feb 18, 2026