CVE-2016-10200: Google Android

High severity, CVSS 7.0. EPSS: 0.3% chance of exploitation in the next 30 days.

Race condition in the L2TPv3 IP Encapsulation feature in the Linux kernel before 4.8.14 allows local users to gain privileges or cause a denial of service (use-after-free) by making multiple bind system calls without properly ascertaining whether a socket has the SOCK_ZAPPED status, related to net/l2tp/l2tp_ip.c and net/l2tp/l2tp_ip6.c.

Affected products

  • Google Android: up to and including 7.1.1
  • Linux Linux Kernel: from 3.0.34, before 3.2 (fixed in 3.2); from 3.2.20, before 3.2.88 (fixed in 3.2.88); from 3.4.2, before 3.12.69 (fixed in 3.12.69); from 3.13, before 3.16.40 (fixed in 3.16.40); from 3.17, before 3.18.52 (fixed in 3.18.52); from 3.19, before 4.4.38 (fixed in 4.4.38); …

Published 2017-03-07. Last modified 2026-06-17.