CVE-2016-10229

critical
Published 2017-04-04 · Modified 2026-05-13
CVSS v3
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2
10.0
VIR risk
9.8

Description

udp.c in the Linux kernel before 4.5 allows remote attackers to execute arbitrary code via UDP traffic that triggers an unsafe second checksum calculation during execution of a recv system call with the MSG_PEEK flag.

Predictions

Exploit likelihood
97%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2016-10229

vendor Authored 2026-05-27

Vendor advisory: security@android.com — https://github.com/torvalds/linux/commit/197c949e7798fbf28cfadc69d9ca0c2abbf93191

vendor Authored 2026-05-27

Vendor advisory: security@android.com — http://source.android.com/security/bulletin/2017-04-01.html

vendor Authored 2026-05-27

Vendor advisory: security@android.com — http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=197c949e7798fbf28cfadc69d9ca0c2abbf93191

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2016-10229.html

OS impact

OSVersionStatusFixed in
suse slesaffected
arch archfixed4.5-1
debian debianbookwormfixed4.5.1-1
debian debianbullseyefixed4.5.1-1
debian debianforkyfixed4.5.1-1
debian debiansidfixed4.5.1-1
debian debiantrixiefixed4.5.1-1
linux linux-kernelaffected3.2.76

References

CWEs

CWE-358

Verify integrity in audit chain (admin only). AS-IS.