CVE-2016-3672: Canonical Ubuntu Linux
High severity, CVSS 7.8. EPSS: 1.2% chance of exploitation in the next 30 days.
The arch_pick_mmap_layout function in arch/x86/mm/mmap.c in the Linux kernel through 4.5.2 does not properly randomize the legacy base address, which makes it easier for local users to defeat the intended restrictions on the ADDR_NO_RANDOMIZE flag, and bypass the ASLR protection mechanism for a setuid or setgid program, by disabling stack-consumption resource limits.
Affected products
- Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 15.10 only
- Linux Linux Kernel: up to and including 4.5.2
- Novell Suse Linux Enterprise Desktop: version 12.0 only
- Novell Suse Linux Enterprise Live Patching: version 12.0 only
- Novell Suse Linux Enterprise Module For Public Cloud: version 12.0 only
- Novell Suse Linux Enterprise Real Time Extension: version 12.0 only
- Novell Suse Linux Enterprise Server: version 12.0 only
- Novell Suse Linux Enterprise Software Development Kit: version 12.0 only
- Novell Suse Linux Enterprise Workstation Extension: version 12.0 only
Published 2016-04-27. Last modified 2026-06-17.