vulnerability
Ubuntu: (CVE-2016-10229): linux vulnerability
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 10 | (AV:N/AC:L/Au:N/C:C/I:C/A:C) | Apr 4, 2017 | Nov 19, 2024 | Sep 1, 2025 |
Severity
10
CVSS
(AV:N/AC:L/Au:N/C:C/I:C/A:C)
Published
Apr 4, 2017
Added
Nov 19, 2024
Modified
Sep 1, 2025
Description
udp.c in the Linux kernel before 4.5 allows remote attackers to execute arbitrary code via UDP traffic that triggers an unsafe second checksum calculation during execution of a recv system call with the MSG_PEEK flag.
Solutions
ubuntu-upgrade-linuxubuntu-upgrade-linux-armadaxpubuntu-upgrade-linux-lts-trustyubuntu-upgrade-linux-lts-vividubuntu-upgrade-linux-ti-omap4
References
- CVE-2016-10229
- https://attackerkb.com/topics/CVE-2016-10229
- CWE-358
- URL-http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=197c949e7798fbf28cfadc69d9ca0c2abbf93191
- URL-http://source.android.com/security/bulletin/2017-04-01.html
- URL-https://github.com/torvalds/linux/commit/197c949e7798fbf28cfadc69d9ca0c2abbf93191
- URL-https://www.cve.org/CVERecord?id=CVE-2016-10229
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.