A vulnerability in net/ipv4/tcp_input.c in the Linux kernel before version 4.7 allows remote attackers to hijack TCP sessions. The kernel does not properly limit the rate of challenge ACK segments, enabling attackers to infer sequence numbers and perform blind in-window attacks to inject or hijack TCP connections.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a proof-of-concept (PoC) exploit for CVE-2016-5696, the 'Off-Path TCP Exploits: Global Rate Limit Considered Dangerous' vulnerability affecting Linux kernels 3.6 to 4.7. The exploit is implemented in C and consists of three main code files: 'mountain_goat.c' (main logic and state machine), 'layers.c' (packet crafting and session management), and 'layers.h' (data structures and function prototypes). The Makefile builds the 'mountain_goat' binary. The exploit works by sending crafted TCP packets (RST, ACK) to a target server and analyzing the responses to infer the TCP sequence number window of an existing connection between a victim and a server. This demonstrates the feasibility of off-path TCP attacks, but does not perform full traffic injection. The tool requires root privileges and raw socket access. No hardcoded IPs or domains are present; all endpoints are provided as command-line arguments. The repository is intended for research and educational purposes only.
This repository is a proof-of-concept exploit for CVE-2016-5696, a vulnerability in the Linux kernel's TCP implementation (versions 3.6 to 4.7) that allows off-path attackers to reset or inject data into TCP connections by exploiting the global challenge ACK rate limit. The main exploit logic is implemented in 'challack.c', which crafts and sends raw TCP packets to infer the four-tuple (source/destination IP and port) and sequence numbers of an existing TCP session between a client and server. Once these parameters are inferred, the attacker can send RST packets to reset the connection or inject arbitrary data. The exploit requires the attacker to be able to spoof packets and to configure their environment (MAC addresses, iptables rules) accordingly. The repository also includes several helper programs under the 'playing/' directory for simulating and optimizing the search for port and sequence numbers. The code is written in C and is intended for research and demonstration purposes, not for weaponized use.
This repository contains a proof-of-concept exploit for CVE-2016-5696, which is a TCP challenge ACK side channel vulnerability affecting Linux kernels. The main file, 'rover.py', is a Python 2.7 script that uses Scapy to craft and send TCP packets to a target server and client. The script attempts to discover the ephemeral source port used by a client in an active TCP connection (such as SSH) to a server. By exploiting the timing and behavior of challenge ACKs, the script can deduce the correct source port, thus completing the 4-tuple (src IP, src port, dst IP, dst port) necessary to identify and potentially hijack or inject into the TCP session. The exploit requires the attacker to have the ability to send raw packets and modify iptables rules to drop RST packets. The README provides usage instructions and notes on requirements and limitations. The repository is structured simply, with a single exploit script and a README file. No hardcoded endpoints are present; all targets are supplied by the user at runtime.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.