High severity7.8NVD Advisory· Published Feb 22, 2017· Updated Jun 17, 2026
CVE-2016-8636
CVE-2016-8636
Description
Integer overflow in the mem_check_range function in drivers/infiniband/sw/rxe/rxe_mr.c in the Linux kernel before 4.9.10 allows local users to cause a denial of service (memory corruption), obtain sensitive information from kernel memory, or possibly have unspecified other impact via a write or read request involving the "RDMA protocol over infiniband" (aka Soft RoCE) technology.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
22- osv-coords20 versionspkg:rpm/suse/kernel-default&distro=SUSE%20Enterprise%20Storage%204pkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2012%20SP2pkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCLpkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-LTSSpkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2pkg:rpm/suse/kernel-default&distro=SUSE%20OpenStack%20Cloud%207pkg:rpm/suse/kernel-source&distro=SUSE%20Enterprise%20Storage%204pkg:rpm/suse/kernel-source&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCLpkg:rpm/suse/kernel-source&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-LTSSpkg:rpm/suse/kernel-source&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2pkg:rpm/suse/kernel-source&distro=SUSE%20OpenStack%20Cloud%207pkg:rpm/suse/kernel-syms&distro=SUSE%20Enterprise%20Storage%204pkg:rpm/suse/kernel-syms&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCLpkg:rpm/suse/kernel-syms&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-LTSSpkg:rpm/suse/kernel-syms&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2pkg:rpm/suse/kernel-syms&distro=SUSE%20OpenStack%20Cloud%207pkg:rpm/suse/kgraft-patch-SLE12-SP2_Update_29&distro=SUSE%20Enterprise%20Storage%204pkg:rpm/suse/kgraft-patch-SLE12-SP2_Update_29&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-LTSSpkg:rpm/suse/kgraft-patch-SLE12-SP2_Update_29&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2pkg:rpm/suse/kgraft-patch-SLE12-SP2_Update_29&distro=SUSE%20OpenStack%20Cloud%207
< 4.4.121-92.109.2+ 19 more
- (no CPE)range: < 4.4.121-92.109.2
- (no CPE)range: < 4.4.121-92.109.2
- (no CPE)range: < 4.4.121-92.109.2
- (no CPE)range: < 4.4.121-92.109.2
- (no CPE)range: < 4.4.121-92.109.2
- (no CPE)range: < 4.4.121-92.109.2
- (no CPE)range: < 4.4.121-92.109.2
- (no CPE)range: < 4.4.121-92.109.2
- (no CPE)range: < 4.4.121-92.109.2
- (no CPE)range: < 4.4.121-92.109.2
- (no CPE)range: < 4.4.121-92.109.2
- (no CPE)range: < 4.4.121-92.109.2
- (no CPE)range: < 4.4.121-92.109.2
- (no CPE)range: < 4.4.121-92.109.2
- (no CPE)range: < 4.4.121-92.109.2
- (no CPE)range: < 4.4.121-92.109.2
- (no CPE)range: < 1-3.5.2
- (no CPE)range: < 1-3.5.2
- (no CPE)range: < 1-3.5.2
- (no CPE)range: < 1-3.5.2
Patches
Vulnerability mechanics
References
7- git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/nvdIssue TrackingPatchThird Party Advisory
- www.openwall.com/lists/oss-security/2017/02/11/9nvdMailing ListPatchThird Party Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingPatch
- eyalitkin.wordpress.com/2017/02/11/cve-publication-cve-2016-8636/nvdPatchTechnical DescriptionThird Party Advisory
- github.com/torvalds/linux/commit/647bf3d8a8e5777319da92af672289b2a6c4dc66nvdIssue TrackingPatchThird Party Advisory
- www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.10nvdRelease NotesVendor Advisory
- www.securityfocus.com/bid/96189nvdThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.