CVE-2016-3841: Google Android
High severity, CVSS 7.3. EPSS: 0.3% chance of exploitation in the next 30 days.
The IPv6 stack in the Linux kernel before 4.3.3 mishandles options data, which allows local users to gain privileges or cause a denial of service (use-after-free and system crash) via a crafted sendmsg system call.
Affected products
- Google Android: version 6.0.1 only
- Linux Linux Kernel: before 3.2.75 (fixed in 3.2.75); from 3.3, before 3.12.52 (fixed in 3.12.52); from 3.13, before 3.16.35 (fixed in 3.16.35); from 3.17, before 3.18.25 (fixed in 3.18.25); from 3.19, before 4.1.15 (fixed in 4.1.15); from 4.2, before 4.2.8 (fixed in 4.2.8); …
Published 2016-08-06. Last modified 2026-06-17.