# CVE-2016-10229: Linux kernel, UDP and use of MSG_PEEK 

 OpenVPN does not make use of the MSG_PEEK feature when processing packets from a remote system, and therefore OpenVPN is not impacted by this bug.

# References 
* http://www.securityfocus.com/bid/97397
* https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=197c949e7798fbf28cfadc69d9ca0c2abbf93191

## Distribution notes 
* Red Hat Enterprise Linux: https://access.redhat.com/solutions/3001781 https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-10229
* SUSE Enterprise Linux: https://www.suse.com/security/cve/CVE-2016-10229/
* Debian: https://security-tracker.debian.org/tracker/CVE-2016-10229
* Ubuntu: https://people.canonical.com/~ubuntu-security/cve/2016/CVE-2016-10229.html
* Arch: https://security.archlinux.org/CVE-2016-10229
* Android: https://source.android.com/security/bulletin/2017-04-01
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9