ZeroHour

CVE-2016-10229

CVSS 3.1
9.8 critical
EPSS
13%p96
Published
()
Modified
Description

udp.c in the Linux kernel before 4.5 allows remote attackers to execute arbitrary code via UDP traffic that triggers an unsafe second checksum calculation during execution of a recv system call with the MSG_PEEK flag.

Vendors
linuxgoogle
Products
linux kernel, android
Weakness
CWE-358
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news