CVE-2016-3672: Canonical Ubuntu Linux

High severity, CVSS 7.8. EPSS: 1.2% chance of exploitation in the next 30 days.

The arch_pick_mmap_layout function in arch/x86/mm/mmap.c in the Linux kernel through 4.5.2 does not properly randomize the legacy base address, which makes it easier for local users to defeat the intended restrictions on the ADDR_NO_RANDOMIZE flag, and bypass the ASLR protection mechanism for a setuid or setgid program, by disabling stack-consumption resource limits.

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 15.10 only
  • Linux Linux Kernel: up to and including 4.5.2
  • Novell Suse Linux Enterprise Desktop: version 12.0 only
  • Novell Suse Linux Enterprise Live Patching: version 12.0 only
  • Novell Suse Linux Enterprise Module For Public Cloud: version 12.0 only
  • Novell Suse Linux Enterprise Real Time Extension: version 12.0 only
  • Novell Suse Linux Enterprise Server: version 12.0 only
  • Novell Suse Linux Enterprise Software Development Kit: version 12.0 only
  • Novell Suse Linux Enterprise Workstation Extension: version 12.0 only

Published 2016-04-27. Last modified 2026-06-17.