CVE-2016-1669: Canonical Ubuntu Linux
High severity, CVSS 8.8. EPSS: 4.2% chance of exploitation in the next 30 days.
The Zone::New function in zone.cc in Google V8 before 5.0.71.47, as used in Google Chrome before 50.0.2661.102, does not properly determine when to expand certain memory allocations, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via crafted JavaScript code.
Affected products
- Canonical Ubuntu Linux: version 14.04 only; version 15.10 only; version 16.04 only
- Debian Debian Linux: version 8.0 only
- Google Chrome: up to and including 50.0.2661.87
- Google v8: up to and including 5.0.71
- Node.js Node.js: from 0.10.0, before 0.10.46 (fixed in 0.10.46); from 0.12.0, before 0.12.15 (fixed in 0.12.15); from 4.0.0, up to and including 4.1.2; from 4.2.0, before 4.4.6 (fixed in 4.4.6); from 5.0.0, before 5.12.0 (fixed in 5.12.0); from 6.0.0, up to and including 6.2.0
- Opensuse Opensuse: version 13.1 only
Published 2016-05-14. Last modified 2026-06-17.