[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-USN-3070-4":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-04T08:53:30.047Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":11,"aliases":12,"duplicate_of":9,"upstream":13,"downstream":46,"duplicates":47,"related":48,"reserved_at":9,"published_at":57,"modified_at":58,"state":9,"summary":59,"references_raw":61,"kevs":101,"epss":9,"epss_history":102,"metrics":103,"affected":104},"USN-3070-4","linux-lts-xenial vulnerabilities\n\nUSN-3070-1 fixed vulnerabilities in the Linux kernel for Ubuntu\n16.04 LTS. This update provides the corresponding updates for the\nLinux Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for\nUbuntu 14.04 LTS.\n\nA missing permission check when settings ACLs was discovered in nfsd. A\nlocal user could exploit this flaw to gain access to any file by setting an\nACL. (CVE-2016-1237)\n\nKangjie Lu discovered an information leak in the Reliable Datagram Sockets\n(RDS) implementation in the Linux kernel. A local attacker could use this\nto obtain potentially sensitive information from kernel memory.\n(CVE-2016-5244)\n\nJames Patrick-Evans discovered that the airspy USB device driver in the\nLinux kernel did not properly handle certain error conditions. An attacker\nwith physical access could use this to cause a denial of service (memory\nconsumption). (CVE-2016-5400)\n\nYue Cao et al discovered a flaw in the TCP implementation's handling of\nchallenge acks in the Linux kernel. A remote attacker could use this to\ncause a denial of service (reset connection) or inject content into an TCP\nstream. (CVE-2016-5696)\n\nPengfei Wang discovered a race condition in the MIC VOP driver in the Linux\nkernel. A local attacker could use this to cause a denial of service\n(system crash) or obtain potentially sensitive information from kernel\nmemory. (CVE-2016-5728)\n\nCyril Bur discovered that on PowerPC platforms, the Linux kernel mishandled\ntransactional memory state on exec(). A local attacker could use this to\ncause a denial of service (system crash) or possibly execute arbitrary\ncode. (CVE-2016-5828)\n\nIt was discovered that a heap based buffer overflow existed in the USB HID\ndriver in the Linux kernel. A local attacker could use this cause a denial\nof service (system crash) or possibly execute arbitrary code.\n(CVE-2016-5829)\n\nIt was discovered that the OverlayFS implementation in the Linux kernel did\nnot properly verify dentry state before proceeding with unlink and rename\noperations. A local attacker could use this to cause a denial of service\n(system crash). (CVE-2016-6197)\n",null,[],[],[],[14,16,18,20,22,24,26,28,30,32,34,36,38,40,42,44],{"_key":15},"CVE-2016-1237",{"_key":17},"CVE-2016-5244",{"_key":19},"CVE-2016-5400",{"_key":21},"CVE-2016-5696",{"_key":23},"CVE-2016-5728",{"_key":25},"CVE-2016-5828",{"_key":27},"CVE-2016-5829",{"_key":29},"CVE-2016-6197",{"_key":31},"UBUNTU-CVE-2016-1237",{"_key":33},"UBUNTU-CVE-2016-5244",{"_key":35},"UBUNTU-CVE-2016-5400",{"_key":37},"UBUNTU-CVE-2016-5696",{"_key":39},"UBUNTU-CVE-2016-5728",{"_key":41},"UBUNTU-CVE-2016-5828",{"_key":43},"UBUNTU-CVE-2016-5829",{"_key":45},"UBUNTU-CVE-2016-6197",[],[],[49,50,51,52,53,54,55,56],{"_key":31},{"_key":35},{"_key":37},{"_key":39},{"_key":41},{"_key":33},{"_key":43},{"_key":45},"2016-08-30T16:47:18.923001Z","2026-02-04T02:29:54.538896Z",{"cisa_kev":60,"cisa_ransomware":60,"cisa_vendor":9,"epss_severity":9,"epss_score":9,"severity":9,"severity_score":9,"severity_version":9,"severity_source":9,"severity_vector":9,"severity_status":9},false,[62,68,73,77,81,85,89,93,97],{"url":63,"sources":64,"tags":66},"https://ubuntu.com/security/notices/USN-3070-4",[65],"osv_ubuntu",[67],"Advisory",{"url":69,"sources":70,"tags":71},"https://ubuntu.com/security/CVE-2016-1237",[65],[72],"REPORT",{"url":74,"sources":75,"tags":76},"https://ubuntu.com/security/CVE-2016-5244",[65],[72],{"url":78,"sources":79,"tags":80},"https://ubuntu.com/security/CVE-2016-5400",[65],[72],{"url":82,"sources":83,"tags":84},"https://ubuntu.com/security/CVE-2016-5696",[65],[72],{"url":86,"sources":87,"tags":88},"https://ubuntu.com/security/CVE-2016-5728",[65],[72],{"url":90,"sources":91,"tags":92},"https://ubuntu.com/security/CVE-2016-5828",[65],[72],{"url":94,"sources":95,"tags":96},"https://ubuntu.com/security/CVE-2016-5829",[65],[72],{"url":98,"sources":99,"tags":100},"https://ubuntu.com/security/CVE-2016-6197",[65],[72],[],[],[],[105],{"ecosystem":106,"name":107,"vendor":108,"product":107,"cpe_part":9,"purl_type":109,"purl_namespace":108,"purl_name":107,"source":9,"versions":110},"Ubuntu","linux-lts-xenial","ubuntu","deb",[111],{"version":112,"is_range":113,"range_type":114,"version_start":9,"version_start_type":9,"version_end":115,"version_end_type":116,"fixed_in":9},"lt4_4_0_36_55~14_04_1",true,"ecosystem","4.4.0-36.55~14.04.1","excluding"]