CVE-2016-5244: Fedoraproject Fedora
High severity, CVSS 7.5. EPSS: 5.5% chance of exploitation in the next 30 days.
The rds_inc_info_copy function in net/rds/recv.c in the Linux kernel through 4.6.3 does not initialize a certain structure member, which allows remote attackers to obtain sensitive information from kernel stack memory by reading an RDS message.
Affected products
- Fedoraproject Fedora: version 23 only; version 24 only; version 22 only
- Linux Linux Kernel: up to and including 4.6.3
- Red Hat Enterprise Linux: version 6.0 only; version 5 only
- Suse Linux Enterprise Debuginfo: version 11 only
- Suse Linux Enterprise Desktop: version 12 only
- Suse Linux Enterprise Real Time Extension: version 11 only; version 12 only
- Suse Linux Enterprise Server: version 11 only
- Suse Linux Enterprise Workstation Extension: version 12 only
- Suse Opensuse Leap: version 42.1 only
- Suse Suse Linux Enterprise Server: version 12 only
- Suse Suse Linux Enterprise Software Development Kit: version 11 only; version 12 only
Published 2016-06-27. Last modified 2026-06-17.