CVE-2016-10088: Linux Kernel

High severity, CVSS 7.0. EPSS: 0.4% chance of exploitation in the next 30 days.

The sg implementation in the Linux kernel through 4.9 does not properly restrict write operations in situations where the KERNEL_DS option is set, which allows local users to read or write to arbitrary kernel memory locations or cause a denial of service (use-after-free) by leveraging access to a /dev/sg device, related to block/bsg.c and drivers/scsi/sg.c. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-9576.

Affected products

  • Linux Linux Kernel: before 3.10.107 (fixed in 3.10.107); from 3.11, before 3.12.70 (fixed in 3.12.70); from 3.13, before 3.16.40 (fixed in 3.16.40); from 3.17, before 3.18.47 (fixed in 3.18.47); from 3.19, before 4.1.38 (fixed in 4.1.38); from 4.2, before 4.4.41 (fixed in 4.4.41); …

Published 2016-12-30. Last modified 2026-06-17.