CVE-2016-10229: Google Android
Critical severity, CVSS 9.8. EPSS: 12.8% chance of exploitation in the next 30 days.
udp.c in the Linux kernel before 4.5 allows remote attackers to execute arbitrary code via UDP traffic that triggers an unsafe second checksum calculation during execution of a recv system call with the MSG_PEEK flag.
Affected products
- Google Android: up to and including 7.1.1
- Linux Linux Kernel: from 3.2, before 3.2.76 (fixed in 3.2.76); from 3.3, before 3.4.113 (fixed in 3.4.113); from 3.5, before 3.10.103 (fixed in 3.10.103); from 3.11, before 3.12.53 (fixed in 3.12.53); from 3.13, before 3.14.77 (fixed in 3.14.77); from 3.15, before 3.16.35 (fixed in 3.16.35); …
Published 2017-04-04. Last modified 2026-06-17.