Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2016-10200 Details

Description

Race condition in the L2TPv3 IP Encapsulation feature in the Linux kernel before 4.8.14 allows local users to gain privileges or cause a denial of service (use-after-free) by making multiple bind system calls without properly ascertaining whether a socket has the SOCK_ZAPPED status, related to net/l2tp/l2tp_ip.c and net/l2tp/l2tp_ip6.c.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=32c231164b762dddefa13af5a0101032c70b50ef CVEIssue TrackingPatchThird Party Advisory
https://access.redhat.com/errata/RHSA-2017:1842 CVEThird Party Advisory
https://access.redhat.com/errata/RHSA-2017:2077 CVEThird Party Advisory
https://access.redhat.com/errata/RHSA-2017:2437 CVEThird Party Advisory
https://access.redhat.com/errata/RHSA-2017:2444 CVEThird Party Advisory

see all 22 references

Weakness Enumeration

CWE-IDCWE NameSource
CWE-264Permissions, Privileges, and Access Controls[email protected]
CWE-362Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')[email protected]
CWE-416Use After Free[email protected]

Affected Products

ProductVersions
linux linux kernel
>= 3.0.34, < 3.2
>= 3.2.20, < 3.2.88
>= 3.4.2, < 3.12.69
>= 3.13, < 3.16.40
>= 3.17, < 3.18.52

CPE

  • cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
google android
<= 7.1.1

CPE

  • cpe:2.3:o:google:android:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

11 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2016-10200
NVD Published Date:
Mar 7, 2017
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]