← All CVEs

CVE-2016-10229

critical · 9.8

udp.c in the Linux kernel before 4.5 allows remote attackers to execute arbitrary code via UDP traffic that triggers an unsafe second checksum calculation during execution of a recv system call with the MSG_PEEK flag.

9.8
CVSS
12.8%
EPSS (exploit prob.)
96th
EPSS percentile
2017-04-04
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-358

Affected products

VendorProductAffected versions
linuxlinux_kernel>= 3.2, < 3.2.76
linuxlinux_kernel>= 3.3, < 3.4.113
linuxlinux_kernel>= 3.5, < 3.10.103
linuxlinux_kernel>= 3.11, < 3.12.53
linuxlinux_kernel>= 3.13, < 3.14.77
linuxlinux_kernel>= 3.15, < 3.16.35
linuxlinux_kernel>= 3.17, < 3.18.45
linuxlinux_kernel>= 3.19, < 4.1.40
linuxlinux_kernel>= 4.2, < 4.4.21
googleandroid<= 7.1.1

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2016-10229