CVE-2016-3947: Canonical Ubuntu Linux

High severity, CVSS 8.2. EPSS: 14.6% chance of exploitation in the next 30 days.

Heap-based buffer overflow in the Icmp6::Recv function in icmp/Icmp6.cc in the pinger utility in Squid before 3.5.16 and 4.x before 4.0.8 allows remote servers to cause a denial of service (performance degradation or transition failures) or write sensitive information to log files via an ICMPv6 packet.

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 15.10 only; version 16.04 only
  • Squid-Cache Squid: up to and including 3.5.15; version 4.0.1 only; version 4.0.2 only; version 4.0.3 only; version 4.0.4 only; version 4.0.5 only; …

Published 2016-04-07. Last modified 2026-06-17.