CVE-2016-6786: Linux Kernel

High severity, CVSS 7.0. EPSS: 0.4% chance of exploitation in the next 30 days.

kernel/events/core.c in the performance subsystem in the Linux kernel before 4.0 mismanages locks during certain migrations, which allows local users to gain privileges via a crafted application, aka Android internal bug 30955111.

Affected products

  • Linux Linux Kernel: before 3.2.85 (fixed in 3.2.85); from 3.3, before 3.16.40 (fixed in 3.16.40); from 3.17, before 3.18.54 (fixed in 3.18.54); from 3.19, before 4.0 (fixed in 4.0)

Published 2016-12-28. Last modified 2026-06-17.