CVE-2016-6252: Shadow Project Shadow

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Integer overflow in shadow 4.2.1 allows local users to gain privileges via crafted input to newuidmap.

Affected products

Published 2017-02-17. Last modified 2026-06-17.