CVE-2016-10229
Last modified
CVE-2016-10229 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. udp.c in the Linux kernel before 4.5 allows remote attackers to execute arbitrary code via UDP traffic that triggers an unsafe second checksum calculation during execution of a recv system call with the MSG_PEEK flag.. EPSS estimates a 12.79% chance of exploitation in the next 30 days.
Description
udp.c in the Linux kernel before 4.5 allows remote attackers to execute arbitrary code via UDP traffic that triggers an unsafe second checksum calculation during execution of a recv system call with the MSG_PEEK flag.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 3.2, < 3.2.76 |
| Linux | Linux Kernel | >= 3.3, < 3.4.113 |
| Linux | Linux Kernel | >= 3.5, < 3.10.103 |
| Linux | Linux Kernel | >= 3.11, < 3.12.53 |
| Linux | Linux Kernel | >= 3.13, < 3.14.77 |
| Linux | Linux Kernel | >= 3.15, < 3.16.35 |
| Linux | Linux Kernel | >= 3.17, < 3.18.45 |
| Linux | Linux Kernel | >= 3.19, < 4.1.40 |
| Linux | Linux Kernel | >= 4.2, < 4.4.21 |
| Android | <= 7.1.1 |
References
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=197c949e7798fbf28cfadc69d9ca0c2abbf93191Issue Tracking, Patch, Third Party Advisory
- http://source.android.com/security/bulletin/2017-04-01.htmlPatch, Third Party Advisory
- http://www.securityfocus.com/bid/97397Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1038201Third Party Advisory, VDB Entry
- https://github.com/torvalds/linux/commit/197c949e7798fbf28cfadc69d9ca0c2abbf93191Issue Tracking, Patch, Third Party Advisory
- https://security.paloaltonetworks.com/CVE-2016-10229Third Party Advisory
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=197c949e7798fbf28cfadc69d9ca0c2abbf93191Issue Tracking, Patch, Third Party Advisory
- http://source.android.com/security/bulletin/2017-04-01.htmlPatch, Third Party Advisory
- http://www.securityfocus.com/bid/97397Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1038201Third Party Advisory, VDB Entry
- https://github.com/torvalds/linux/commit/197c949e7798fbf28cfadc69d9ca0c2abbf93191Issue Tracking, Patch, Third Party Advisory
- https://security.paloaltonetworks.com/CVE-2016-10229Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-10229?
How severe is CVE-2016-10229?
How do I fix CVE-2016-10229?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2016
- CVE-2016-10223An issue was discovered in BigTree CMS before 4.2.15. The vu…
- CVE-2016-10224An issue was discovered in Sauter NovaWeb web HMI. The appli…7.2
- CVE-2016-10225The sunxi-debug driver in Allwinner 3.4 legacy kernel for H3…7.8
- CVE-2016-10226JavaScriptCore in WebKit, as distributed in Safari Technolog…
- CVE-2016-10227Zyxel USG50 Security Appliance and NWA3560-N Access Point al…
- CVE-2016-10228The iconv program in the GNU C Library (aka glibc or libc6) …
- CVE-2016-1023Adobe Flash Player before 18.0.0.343 and 19.x through 21.x b…8.8
- CVE-2016-10230A remote code execution vulnerability in the Qualcomm crypto…
- CVE-2016-10231An elevation of privilege vulnerability in the Qualcomm soun…
- CVE-2016-10232An elevation of privilege vulnerability in the Qualcomm vide…
- CVE-2016-10233An elevation of privilege vulnerability in the Qualcomm vide…
- CVE-2016-10234An information disclosure vulnerability in the Qualcomm IPA …
Are you affected by CVE-2016-10229?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
