udp.c in the Linux kernel before 4.5 allows remote attackers to execute arbitrary code via UDP traffic that triggers an unsafe second checksum calculation during execution of a recv system call with the MSG_PEEK flag.
2017-04-04T05:59:00.233
2025-04-20T01:37:25.860
Deferred
CVSSv3.1: 9.8 (CRITICAL)
AV:N/AC:L/Au:N/C:C/I:C/A:C
10.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | linux | linux_kernel | < 3.2.76 | Yes |
Operating System | linux | linux_kernel | < 3.4.113 | Yes |
Operating System | linux | linux_kernel | < 3.10.103 | Yes |
Operating System | linux | linux_kernel | < 3.12.53 | Yes |
Operating System | linux | linux_kernel | < 3.14.77 | Yes |
Operating System | linux | linux_kernel | < 3.16.35 | Yes |
Operating System | linux | linux_kernel | < 3.18.45 | Yes |
Operating System | linux | linux_kernel | < 4.1.40 | Yes |
Operating System | linux | linux_kernel | < 4.4.21 | Yes |
Operating System | android | ≤ 7.1.1 | Yes |