CVE-2016-8632: Linux Kernel

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

The tipc_msg_build function in net/tipc/msg.c in the Linux kernel through 4.8.11 does not validate the relationship between the minimum fragment length and the maximum packet size, which allows local users to gain privileges or cause a denial of service (heap-based buffer overflow) by leveraging the CAP_NET_ADMIN capability.

Affected products

  • Linux Linux Kernel: from 2.6.16, before 3.2.85 (fixed in 3.2.85); from 3.3, before 3.16.40 (fixed in 3.16.40); from 3.17, before 4.1.37 (fixed in 4.1.37); from 4.2, before 4.4.65 (fixed in 4.4.65); from 4.5, before 4.8.14 (fixed in 4.8.14)

Published 2016-11-28. Last modified 2026-06-17.