CVE-2016-9919: Linux Kernel

High severity, CVSS 7.5. EPSS: 5.7% chance of exploitation in the next 30 days.

The icmp6_send function in net/ipv6/icmp.c in the Linux kernel through 4.8.12 omits a certain check of the dst data structure, which allows remote attackers to cause a denial of service (panic) via a fragmented IPv6 packet.

Affected products

  • Linux Linux Kernel: from 4.8.10, before 4.9 (fixed in 4.9); version 4.4.223 only; version 4.9 only

Published 2016-12-08. Last modified 2026-06-17.