imPC@ndo IT

Tracker / CVE-2016-10229

CVE-2016-10229

Critical 9.8

udp.c in the Linux kernel before 4.5 allows remote attackers to execute arbitrary code via UDP traffic that triggers an unsafe second checksum calculation during execution of a recv system call with the MSG_PEEK flag.

Affected products and versions

google android · … → 7.1.1
linux linux_kernel · 3.11 → 3.12.53
linux linux_kernel · 3.13 → 3.14.77
linux linux_kernel · 3.15 → 3.16.35
linux linux_kernel · 3.17 → 3.18.45
linux linux_kernel · 3.19 → 4.1.40
linux linux_kernel · 3.2 → 3.2.76
linux linux_kernel · 3.3 → 3.4.113
linux linux_kernel · 3.5 → 3.10.103
linux linux_kernel · 4.2 → 4.4.21

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References