udp.c in the Linux kernel before 4.5 allows remote attackers to execute arbitrary code via UDP traffic that triggers an unsafe second checksum calculation during execution of a recv system call with the MSG_PEEK flag.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade linux-grsec | Oct 1, 2024 | Apr 4, 2017 |
| Amazon_linux | — | Upgrade kernel | May 31, 2017 | Apr 4, 2017 |
| Debian | — | Upgrade linux | Jul 30, 2024 | Apr 4, 2017 |
| Oracle_linux | — | Upgrade kernel-uek | Apr 13, 2017 | Dec 30, 2015 |
| Panos | — | Update PAN-OS 8.0 to the latest workaround for your deviceUpdate PAN-OS 6.1 to the latest workaround for your deviceUpdate PAN-OS 7.1 to the latest workaround for your device | Jun 19, 2017 | Apr 4, 2017 |
| Suse | — | Upgrade kernel-ec2Upgrade kernel-defaultUpgrade kernel-ec2-develUpgrade kernel-ec2-extra | Nov 2, 2017 | Apr 4, 2017 |
| Ubuntu | — | Upgrade linux-lts-trustyUpgrade linux-lts-vividUpgrade linuxUpgrade linux-ti-omap4Upgrade linux-armadaxp | Nov 19, 2024 | Apr 4, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub