CVE
- Id
- 96613
- CVE No.
- CVE-2016-9793
- Status
- Candidate
- Description
- The sock_setsockopt function in net/core/sock.c in the Linux kernel before 4.8.14 mishandles negative values of sk_sndbuf and sk_rcvbuf, which allows local users to cause a denial of service (memory corruption and system crash) or possibly have unspecified other impact by leveraging the CAP_NET_ADMIN capability for a crafted setsockopt system call with the (1) SO_SNDBUFFORCE or (2) SO_RCVBUFFORCE option.
- Phase
- Assigned (20161202)
- Votes
- None (candidate not yet proposed)
- Comments