CVE-2016-4997: Canonical Ubuntu Linux
High severity, CVSS 7.8. EPSS: 7% chance of exploitation in the next 30 days.
The compat IPT_SO_SET_REPLACE and IP6T_SO_SET_REPLACE setsockopt implementations in the netfilter subsystem in the Linux kernel before 4.6.3 allow local users to gain privileges or cause a denial of service (memory corruption) by leveraging in-container root access to provide a crafted offset value that triggers an unintended decrement.
Affected products
- Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 15.10 only; version 16.04 only
- Debian Debian Linux: version 8.0 only
- Linux Linux Kernel: from 2.6.17, before 3.2.80 (fixed in 3.2.80); from 3.3, before 3.10.103 (fixed in 3.10.103); from 3.11, before 3.12.62 (fixed in 3.12.62); from 3.13, before 3.14.73 (fixed in 3.14.73); from 3.15, before 3.16.37 (fixed in 3.16.37); from 3.17, before 3.18.37 (fixed in 3.18.37); …
- Novell Suse Linux Enterprise Desktop: version 12.0 only
- Novell Suse Linux Enterprise Live Patching: version 12.0 only
- Novell Suse Linux Enterprise Module For Public Cloud: version 12.0 only
- Novell Suse Linux Enterprise Real Time Extension: version 12.0 only
- Novell Suse Linux Enterprise Server: version 12.0 only
- Novell Suse Linux Enterprise Software Development Kit: version 12.0 only
- Novell Suse Linux Enterprise Workstation Extension: version 12.0 only
- Oracle Linux: version 7 only
Published 2016-07-03. Last modified 2026-06-17.