CVE detail
CVE-2016-5696
net/ipv4/tcp_input.c in the Linux kernel before 4.7 does not properly determine the rate of challenge ACK segments, which makes it easier for remote attackers to hijack TCP sessions via a blind in-window attack.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 23.0 · diversity 9.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
9 source links · newest first
- Another Old Flaw Patched in Linux KernelSecurityWeek
A researcher has identified another potentially serious Linux kernel vulnerability that has been around for several years. The flaw was addressed in the kernel more than one week ago, but some of the affected Linux distributions have yet to release patches.
newswww.securityweek.comMar 16, 2017, 5:28 PM - Week in review: Hacking smart cities, leaked hacking tools, and detecting hardware TrojansHelp Net Security
Here’s an overview of some of last week’s most interesting news and articles: eBook: Defending against crypto ransomware Download your copy of the Defending against crypto ransomware eBook and get a walkthrough on how ransomware is delivered to a user’s computer, stages of crypto-ransomware infection, and best practices that can be applied immediately. Proxy authentication flaw can be exploited to crack HTTPS protection Mistakes made in the implementation of proxy authentication in a variety of … More →
newswww.helpnetsecurity.comAug 22, 2016, 12:00 PM - A week in security (Aug 14 – Aug 20)Malwarebytes Labs
Last week, we published two blog posts about the Shakti Trojan: first, an overview of what it is (an information stealer…
newswww.malwarebytes.comAug 21, 2016, 5:00 PM Experts from Lookout revealed that all Android versions running the Linux Kernel 3.6 to the latest are affected by the CVE-2016-569 Linux flaw. Recently I wrote about a severe vulnerability (CVE-2016-5696) affecting the Linux version 3.6, deployed in 2012. The flaw was discovered by researchers from the University of California, Riverside, and the U.S. Army […]
newssecurityaffairs.comAug 17, 2016, 6:28 AM- Attackers can hijack unencrypted web traffic of 80% of Android usersHelp Net Security
The recently revealed security bug (CVE-2016-5696) in the TCP implementation in the Linux kernel that could allow attackers to hijack unencrypted web traffic without an MitM position also affects some 1.4 billion Android devices, Lookout researchers have warned. “We can estimate then that all Android versions running the Linux Kernel 3.6 (approximately Android 4.4 KitKat) to the latest are vulnerable to this attack or 79.9% of the Android ecosystem,” they noted. This fact should not … More →
newswww.helpnetsecurity.comAug 16, 2016, 9:47 AM A recently disclosed Linux kernel vulnerability caused by a TCP feature affects nearly 80 percent of Android devices, according to mobile security firm Lookout.
newswww.securityweek.comAug 16, 2016, 9:43 AMFacebook has announced the winner of its 2016 Internet Defense Prize. This year, the $100,000 reward went to a team of researchers whose work has focused on post-quantum security for TLS.
newswww.securityweek.comAug 15, 2016, 4:27 PMResearchers discovered that a Transmission Control Protocol (TCP) specification implemented in Linux creates a vulnerability that can be exploited to terminate connections and conduct data injection attacks.
newswww.securityweek.comAug 11, 2016, 10:10 AM- Serious Linux design flaw CVE-2016-569 allows Traffic HijackingSecurity Affairs
A severe design flaw in the Linux kernel could be exploited by attackers to hijack traffic, inject malware into connections, and run a wide range of attacks. A severe flaw in the Linux kernel could be exploited by attackers to hijack traffic, inject malware into downloads and web pages, and run a wide range of […]
newssecurityaffairs.comAug 11, 2016, 8:47 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2017-5075CVSS 4.3 · Medium
Inappropriate implementation in CSP reporting in Blink in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android, allowed a remote attacker…
- CVE-2017-0451CVSS 4.7 · Medium
An information disclosure vulnerability in the Qualcomm sound driver could enable a local malicious application to access data outside of its permission levels. This issue is rate…
- CVE-2017-0448CVSS 5.5 · Medium
An information disclosure vulnerability in the NVIDIA video driver could enable a local malicious application to access data outside of its permission levels. This issue is rated…
- CVE-2016-8414CVSS 4.7 · Medium
An information disclosure vulnerability in the Qualcomm Secure Execution Environment Communicator could enable a local malicious application to access data outside of its permissi…
- CVE-2015-8944CVSS 5.5 · Medium
The ioresources_init function in kernel/resource.c in the Linux kernel through 4.7, as used in Android before 2016-08-05 on Nexus 6 and 7 (2013) devices, uses weak permissions for…
- CVE-2014-9900CVSS 5.5 · Medium
The ethtool_get_wol function in net/core/ethtool.c in the Linux kernel through 4.7, as used in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices, does not initialize a cer…