{"id":"CVE-2016-10229","details":"udp.c in the Linux kernel before 4.5 allows remote attackers to execute arbitrary code via UDP traffic that triggers an unsafe second checksum calculation during execution of a recv system call with the MSG_PEEK flag.","modified":"2026-03-12T22:11:26.515897Z","published":"2017-04-04T05:59:00.233Z","related":["SUSE-SU-2017:2920-1"],"references":[{"type":"ADVISORY","url":"https://security.paloaltonetworks.com/CVE-2016-10229"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20250103-0008/"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/97397"},{"type":"ADVISORY","url":"http://www.securitytracker.com/id/1038201"},{"type":"FIX","url":"https://github.com/torvalds/linux/commit/197c949e7798fbf28cfadc69d9ca0c2abbf93191"},{"type":"FIX","url":"http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=197c949e7798fbf28cfadc69d9ca0c2abbf93191"},{"type":"FIX","url":"http://source.android.com/security/bulletin/2017-04-01.html"}],"affected":[{"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-10229.json","unresolved_ranges":[{"events":[{"introduced":"3.2"},{"fixed":"3.2.76"}]},{"events":[{"introduced":"3.3"},{"fixed":"3.4.113"}]},{"events":[{"introduced":"3.5"},{"fixed":"3.10.103"}]},{"events":[{"introduced":"3.11"},{"fixed":"3.12.53"}]},{"events":[{"introduced":"3.13"},{"fixed":"3.14.77"}]},{"events":[{"introduced":"3.15"},{"fixed":"3.16.35"}]},{"events":[{"introduced":"3.17"},{"fixed":"3.18.45"}]},{"events":[{"introduced":"3.19"},{"fixed":"4.1.40"}]},{"events":[{"introduced":"4.2"},{"fixed":"4.4.21"}]},{"events":[{"introduced":"0"},{"last_affected":"7.1.1"}]}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}