CVE-2016-8399: Linux Kernel
High severity, CVSS 7.0. EPSS: 2.3% chance of exploitation in the next 30 days.
An elevation of privilege vulnerability in the kernel networking subsystem could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Moderate because it first requires compromising a privileged process and current compiler optimizations restrict access to the vulnerable code. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-31349935.
Affected products
- Linux Linux Kernel: from 3.19, before 4.1.37 (fixed in 4.1.37); from 4.2, before 4.4.38 (fixed in 4.4.38); from 4.5, before 4.8.14 (fixed in 4.8.14)
Published 2017-01-12. Last modified 2026-06-17.