CVE-2016-5244: Fedoraproject Fedora

High severity, CVSS 7.5. EPSS: 5.5% chance of exploitation in the next 30 days.

The rds_inc_info_copy function in net/rds/recv.c in the Linux kernel through 4.6.3 does not initialize a certain structure member, which allows remote attackers to obtain sensitive information from kernel stack memory by reading an RDS message.

Affected products

  • Fedoraproject Fedora: version 23 only; version 24 only; version 22 only
  • Linux Linux Kernel: up to and including 4.6.3
  • Red Hat Enterprise Linux: version 6.0 only; version 5 only
  • Suse Linux Enterprise Debuginfo: version 11 only
  • Suse Linux Enterprise Desktop: version 12 only
  • Suse Linux Enterprise Real Time Extension: version 11 only; version 12 only
  • Suse Linux Enterprise Server: version 11 only
  • Suse Linux Enterprise Workstation Extension: version 12 only
  • Suse Opensuse Leap: version 42.1 only
  • Suse Suse Linux Enterprise Server: version 12 only
  • Suse Suse Linux Enterprise Software Development Kit: version 11 only; version 12 only

Published 2016-06-27. Last modified 2026-06-17.