CVE-2016-5828: Canonical Ubuntu Linux

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

The start_thread function in arch/powerpc/kernel/process.c in the Linux kernel through 4.6.3 on powerpc platforms mishandles transactional state, which allows local users to cause a denial of service (invalid process state or TM Bad Thing exception, and system crash) or possibly have unspecified other impact by starting and suspending a transaction before an exec system call.

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 16.04 only
  • Debian Debian Linux: version 8.0 only
  • Linux Linux Kernel: from 3.9, before 3.10.103 (fixed in 3.10.103); from 3.11, before 3.14.74 (fixed in 3.14.74); from 3.15, before 3.16.37 (fixed in 3.16.37); from 3.17, before 3.18.37 (fixed in 3.18.37); from 3.19, before 4.1.28 (fixed in 4.1.28); from 4.2, before 4.4.16 (fixed in 4.4.16); …
  • Novell Suse Linux Enterprise Real Time Extension: version 12 only

Published 2016-06-27. Last modified 2026-06-17.