CVE-2016-7117: Canonical Ubuntu Linux

Critical severity, CVSS 9.8. EPSS: 23.6% chance of exploitation in the next 30 days.

Use-after-free vulnerability in the __sys_recvmmsg function in net/socket.c in the Linux kernel before 4.5.2 allows remote attackers to execute arbitrary code via vectors involving a recvmmsg system call that is mishandled during error processing.

Affected products

  • Canonical Ubuntu Linux: version 16.04 only
  • Debian Debian Linux: version 7.0 only
  • Linux Linux Kernel: from 2.6.33, before 3.2.80 (fixed in 3.2.80); from 3.3, before 3.4.113 (fixed in 3.4.113); from 3.5, before 3.10.102 (fixed in 3.10.102); from 3.11, before 3.12.59 (fixed in 3.12.59); from 3.13, before 3.14.67 (fixed in 3.14.67); from 3.15, before 3.16.35 (fixed in 3.16.35); …

Published 2016-10-10. Last modified 2026-06-17.