Medium severity4.8NVD Advisory· Published Aug 6, 2016· Updated May 6, 2026
CVE-2016-5696
CVE-2016-5696
Description
net/ipv4/tcp_input.c in the Linux kernel before 4.7 does not properly determine the rate of challenge ACK segments, which makes it easier for remote attackers to hijack TCP sessions via a blind in-window attack.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
31- git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/nvdIssue TrackingPatch
- github.com/torvalds/linux/commit/75ff39ccc1bd5d3c455b6822ab09e533c551f758nvdIssue TrackingPatch
- source.android.com/security/bulletin/2016-10-01.htmlnvdThird Party Advisory
- www.openwall.com/lists/oss-security/2016/07/12/2nvdMailing ListThird Party Advisory
- www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.htmlnvdThird Party Advisory
- www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlnvdVendor Advisory
- www.prnewswire.com/news-releases/mitnick-attack-reappears-at-geekpwn-macau-contest-300270779.htmlnvdTechnical Description
- bugzilla.redhat.com/show_bug.cginvdIssue Tracking
- www.usenix.org/system/files/conference/usenixsecurity16/sec16_paper_cao.pdfnvdTechnical Description
- rhn.redhat.com/errata/RHSA-2016-1631.htmlnvd
- rhn.redhat.com/errata/RHSA-2016-1632.htmlnvd
- rhn.redhat.com/errata/RHSA-2016-1633.htmlnvd
- rhn.redhat.com/errata/RHSA-2016-1657.htmlnvd
- rhn.redhat.com/errata/RHSA-2016-1664.htmlnvd
- rhn.redhat.com/errata/RHSA-2016-1814.htmlnvd
- rhn.redhat.com/errata/RHSA-2016-1815.htmlnvd
- rhn.redhat.com/errata/RHSA-2016-1939.htmlnvd
- www.securityfocus.com/bid/91704nvd
- www.securitytracker.com/id/1036625nvd
- www.ubuntu.com/usn/USN-3070-1nvd
- www.ubuntu.com/usn/USN-3070-2nvd
- www.ubuntu.com/usn/USN-3070-3nvd
- www.ubuntu.com/usn/USN-3070-4nvd
- www.ubuntu.com/usn/USN-3071-1nvd
- www.ubuntu.com/usn/USN-3071-2nvd
- www.ubuntu.com/usn/USN-3072-1nvd
- www.ubuntu.com/usn/USN-3072-2nvd
- bto.bluecoat.com/security-advisory/sa131nvd
- kc.mcafee.com/corporate/indexnvd
- security.paloaltonetworks.com/CVE-2016-5696nvd
- www.arista.com/en/support/advisories-notices/security-advisories/1461-security-advisory-23nvd
News mentions
0No linked articles in our index yet.