suse · CVE-2016-3134

Quick triage

Priority: medium Published: 2021-05-30 13:40:25 UTC Updated: 2025-05-17 23:59:49 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2016-3134 severity moderate: SUSE including 261 source package names (kernel-3.10.0-327.36.1.el7, kernel-abi-whitelists-3.10.0-327.36.1.el7, …), 668 product×package rows across 98 product lines (SUSE CaaS Platform 4.0, SUSE CaaS Platform 4.5, … (98 product lines)): Fixed 419, Known Not Affected 249.

Description:

The netfilter subsystem in the Linux kernel through 4.5.2 does not validate certain offset fields, which allows local users to gain privileges or cause a denial of service (heap memory corruption) via an IPT_SO_SET_REPLACE setsockopt call.

cvelogic Threat Intelligence