CVE-2016-3698: Canonical Ubuntu Linux

High severity, CVSS 8.1. EPSS: 3.8% chance of exploitation in the next 30 days.

libndp before 1.6, as used in NetworkManager, does not properly validate the origin of Neighbor Discovery Protocol (NDP) messages, which allows remote attackers to conduct man-in-the-middle attacks or cause a denial of service (network connectivity disruption) by advertising a node as a router from a non-local network.

Affected products

  • Canonical Ubuntu Linux: version 15.10 only; version 16.04 only
  • Debian Debian Linux: version 8.0 only
  • Libndp Libndp: up to and including 1.5
  • Red Hat Enterprise Linux Desktop: version 7.0 only
  • Red Hat Enterprise Linux Hpc Node: version 7.0 only
  • Red Hat Enterprise Linux Hpc Node Eus: version 7.2 only
  • Red Hat Enterprise Linux Server: version 7.0 only
  • Red Hat Enterprise Linux Server Aus: version 7.2 only
  • Red Hat Enterprise Linux Server Eus: version 7.2 only
  • Red Hat Enterprise Linux Workstation: version 7.0 only

Published 2016-06-13. Last modified 2026-06-17.