---
cve: "CVE-2016-8655"
severity: "LOW"
cvss: 3.1
epss: "11.1%"
vendor: "n/a"
kev: false
exploited: false
published: "2016-12-08 08:59:00"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-13T10:36:08+02:00"
---

# CVE-2016-8655

> 3.1 LOW · 🧪 PoC

## Beschreibung

Race condition in net/packet/af_packet.c in the Linux kernel through 4.8.12 allows local users to gain privileges or cause a denial of service (use-after-free) by leveraging the CAP_NET_RAW capability to change a socket version, related to the packet_set_ring and packet_setsockopt functions.

## Exploit-Evidenz

- [EDB-44696 — Linux 4.4.0 < 4.4.0-53 - 'AF_PACKET chocobo_root' Local Privilege Escalation (Metasploit)](https://www.exploit-db.com/exploits/44696) ✅
- [EDB-40871 — Linux Kernel 4.4.0 (Ubuntu 14.04/16.04 x86-64) - 'AF_PACKET' Race Condition Privilege Escalation](https://www.exploit-db.com/exploits/40871) ✅
- [EDB-47170 — Linux Kernel 4.4.0-21 < 4.4.0-51 (Ubuntu 14.04/16.04 x64) - 'AF_PACKET' Race Condition Privilege Escalation](https://www.exploit-db.com/exploits/47170)

## Referenzen

- <http://www.ubuntu.com/usn/USN-3151-3>
- <http://lists.opensuse.org/opensuse-security-announce/2016-12/msg00044.html>
- <https://github.com/torvalds/linux/commit/84ac7260236a49c79eede91617700174c2c19b0c>
- <http://lists.opensuse.org/opensuse-security-announce/2016-12/msg00077.html>
- <http://lists.opensuse.org/opensuse-security-announce/2016-12/msg00067.html>
- <http://www.ubuntu.com/usn/USN-3150-2>
- <http://www.ubuntu.com/usn/USN-3149-2>
- <http://www.securityfocus.com/bid/94692>
- <http://www.securitytracker.com/id/1037968>
- <http://www.ubuntu.com/usn/USN-3150-1>
- <http://lists.opensuse.org/opensuse-security-announce/2016-12/msg00056.html>
- <http://lists.opensuse.org/opensuse-security-announce/2016-12/msg00073.html>
- <http://rhn.redhat.com/errata/RHSA-2017-0402.html>
- <http://www.ubuntu.com/usn/USN-3151-1>
- <http://rhn.redhat.com/errata/RHSA-2017-0387.html>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2016-8655) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
