CVE-2016-2070: Linux Kernel
High severity, CVSS 7.5. EPSS: 3.3% chance of exploitation in the next 30 days.
The tcp_cwnd_reduction function in net/ipv4/tcp_input.c in the Linux kernel before 4.3.5 allows remote attackers to cause a denial of service (divide-by-zero error and system crash) via crafted TCP traffic.
Affected products
- Linux Linux Kernel: from 4.3, before 4.3.5 (fixed in 4.3.5)
Published 2016-05-02. Last modified 2026-06-17.