suse · CVE-2016-10229

Quick triage

Priority: critical Published: 2021-05-30 13:49:23 UTC Updated: 2024-10-23 01:17:15 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2016-10229 severity critical: SUSE including 29 source package names (kernel-default, kernel-default-3.12.61-52.101.1, …), 200 product×package rows across 39 product lines (SUSE CaaS Platform 4.0, SUSE Enterprise Storage 6, … (39 product lines)): Known Not Affected 184, Fixed 16.

Description:

udp.c in the Linux kernel before 4.5 allows remote attackers to execute arbitrary code via UDP traffic that triggers an unsafe second checksum calculation during execution of a recv system call with the MSG_PEEK flag.

cvelogic Threat Intelligence