CVE-2016-4998: Canonical Ubuntu Linux
High severity, CVSS 7.1. EPSS: 1.9% chance of exploitation in the next 30 days.
The IPT_SO_SET_REPLACE setsockopt implementation in the netfilter subsystem in the Linux kernel before 4.6 allows local users to cause a denial of service (out-of-bounds read) or possibly obtain sensitive information from kernel heap memory by leveraging in-container root access to provide a crafted offset value that leads to crossing a ruleset blob boundary.
Affected products
- Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 15.10 only; version 16.04 only
- Linux Linux Kernel: up to and including 4.5.5
- Oracle Linux: version 7 only
Published 2016-07-03. Last modified 2026-06-17.