Vulnerability Description
udp.c in the Linux kernel before 4.5 allows remote attackers to execute arbitrary code via UDP traffic that triggers an unsafe second checksum calculation during execution of a recv system call with the MSG_PEEK flag.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 3.2, < 3.2.76 |
| Android | <= 7.1.1 |
Related Weaknesses (CWE)
References
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=197c94Issue TrackingPatchThird Party Advisory
- http://source.android.com/security/bulletin/2017-04-01.htmlPatchThird Party Advisory
- http://www.securityfocus.com/bid/97397Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1038201Third Party AdvisoryVDB Entry
- https://github.com/torvalds/linux/commit/197c949e7798fbf28cfadc69d9ca0c2abbf9319Issue TrackingPatchThird Party Advisory
- https://security.paloaltonetworks.com/CVE-2016-10229Third Party Advisory
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=197c94Issue TrackingPatchThird Party Advisory
- http://source.android.com/security/bulletin/2017-04-01.htmlPatchThird Party Advisory
- http://www.securityfocus.com/bid/97397Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1038201Third Party AdvisoryVDB Entry
- https://github.com/torvalds/linux/commit/197c949e7798fbf28cfadc69d9ca0c2abbf9319Issue TrackingPatchThird Party Advisory
- https://security.netapp.com/advisory/ntap-20250103-0008/
- https://security.paloaltonetworks.com/CVE-2016-10229Third Party Advisory
FAQ
What is CVE-2016-10229?
CVE-2016-10229 is a vulnerability with a CVSS score of 9.8 (CRITICAL). udp.c in the Linux kernel before 4.5 allows remote attackers to execute arbitrary code via UDP traffic that triggers an unsafe second checksum calculation during execution of a recv system call with t...
How severe is CVE-2016-10229?
CVE-2016-10229 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2016-10229?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Google Android.