Linux fixed CVE-2016-3672, a flaw that allowed users on x86 systems to disable Address Space Layout Randomization (ASLR) when launching 32-bit applications by setting the RLIMIT_STACK resource limit to unlimited. The issue was reported by Hector Marco-Gisbert and affected then-current Linux systems.
By disabling ASLR, the condition made process memory locations predictable and weakened a key exploit mitigation, increasing the reliability of memory-corruption attacks. Organizations running affected Linux kernels should apply the available kernel updates, particularly where untrusted users can execute 32-bit binaries.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Hector Marco-Gisbert disclosed CVE-2016-3672 on the Bugtraq mailing list, describing the Linux ASLR bypass that remained present in then-current systems.
Hector Marco-Gisbert reported that a longstanding Linux x86 ASLR weakness, in which users running 32-bit applications could disable ASLR by setting RLIMIT_STACK to unlimited, had been fixed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.