CVE-2016-9806: Linux Kernel
High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.
Race condition in the netlink_dump function in net/netlink/af_netlink.c in the Linux kernel before 4.6.3 allows local users to cause a denial of service (double free) or possibly have unspecified other impact via a crafted application that makes sendmsg system calls, leading to a free operation associated with a new dump that started earlier than anticipated.
Affected products
- Linux Linux Kernel: from 3.12, before 3.12.62 (fixed in 3.12.62); from 3.13, before 3.14.73 (fixed in 3.14.73); from 3.15, before 3.16.37 (fixed in 3.16.37); from 3.17, before 3.18.37 (fixed in 3.18.37); from 3.19, before 4.1.28 (fixed in 4.1.28); from 4.2, before 4.4.14 (fixed in 4.4.14); …
Published 2016-12-28. Last modified 2026-06-17.