CVE-2016-1678: Canonical Ubuntu Linux

High severity, CVSS 8.8. EPSS: 1.6% chance of exploitation in the next 30 days.

objects.cc in Google V8 before 5.0.71.32, as used in Google Chrome before 51.0.2704.63, does not properly restrict lazy deoptimization, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted JavaScript code.

Affected products

  • Canonical Ubuntu Linux: version 14.04 only; version 15.10 only; version 16.04 only
  • Debian Debian Linux: version 8.0 only
  • Google Chrome: up to and including 50.0.2661.102
  • Google v8: up to and including 5.0.71
  • Opensuse Leap: version 42.1 only
  • Opensuse Opensuse: version 13.2 only
  • Red Hat Enterprise Linux Desktop: version 6.0 only
  • Red Hat Enterprise Linux Server: version 6.0 only
  • Red Hat Enterprise Linux Workstation: version 6.0 only
  • Suse Linux Enterprise: version 12.0 only

Published 2016-06-05. Last modified 2026-06-17.