CVE-2016-6187: Linux Kernel

High severity, CVSS 7.8. EPSS: 2.4% chance of exploitation in the next 30 days.

The apparmor_setprocattr function in security/apparmor/lsm.c in the Linux kernel before 4.6.5 does not validate the buffer size, which allows local users to gain privileges by triggering an AppArmor setprocattr hook.

Affected products

  • Linux Linux Kernel: from 4.5, before 4.6.5 (fixed in 4.6.5)

Published 2016-08-06. Last modified 2026-06-17.