CVE-2016-8398: Linux Kernel

Critical severity, CVSS 9.8. EPSS: 1.6% chance of exploitation in the next 30 days.

Unauthenticated messages processed by the UE. Certain NAS messages are processed when no EPS security context exists in the UE. Product: Android. Versions: Kernel 3.18. Android ID: A-31548486. References: QC-CR#877705.

Affected products

  • Linux Linux Kernel: version 3.18 only

Published 2017-01-12. Last modified 2026-06-17.