CVE-2016-9644: Linux Kernel

High severity, CVSS 7.8. EPSS: 1.5% chance of exploitation in the next 30 days.

The __get_user_asm_ex macro in arch/x86/include/asm/uaccess.h in the Linux kernel 4.4.22 through 4.4.28 contains extended asm statements that are incompatible with the exception table, which allows local users to obtain root access on non-SMEP platforms via a crafted application. NOTE: this vulnerability exists because of incorrect backporting of the CVE-2016-9178 patch to older kernels.

Affected products

  • Linux Linux Kernel: version 4.4.22 only; version 4.4.23 only; version 4.4.24 only; version 4.4.25 only; version 4.4.26 only; version 4.4.27 only; …

Published 2016-11-28. Last modified 2026-06-17.