CVE-2016-8636: Linux Kernel
High severity, CVSS 7.8. EPSS: 1.2% chance of exploitation in the next 30 days.
Integer overflow in the mem_check_range function in drivers/infiniband/sw/rxe/rxe_mr.c in the Linux kernel before 4.9.10 allows local users to cause a denial of service (memory corruption), obtain sensitive information from kernel memory, or possibly have unspecified other impact via a write or read request involving the "RDMA protocol over infiniband" (aka Soft RoCE) technology.
Affected products
- Linux Linux Kernel: from 4.8, before 4.9.10 (fixed in 4.9.10)
Published 2017-02-22. Last modified 2026-06-17.