VYPR
High severity7.5NVD Advisory· Published Dec 8, 2016· Updated May 6, 2026

CVE-2016-9919

CVE-2016-9919

Description

The icmp6_send function in net/ipv6/icmp.c in the Linux kernel through 4.8.12 omits a certain check of the dst data structure, which allows remote attackers to cause a denial of service (panic) via a fragmented IPv6 packet.

Affected products

4
  • Linux/Kernel4 versions
    cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: >=4.8.10,<4.9
    • cpe:2.3:o:linux:linux_kernel:4.4.223:*:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:4.9:rc6:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:4.9:rc7:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.