CVE-2016-10229: Linux kernel, UDP and use of MSG_PEEK
OpenVPN does not make use of the MSG_PEEK feature when processing packets from a remote system, and therefore OpenVPN is not impacted by this bug.
References
- http://www.securityfocus.com/bid/97397
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=197c949e7798fbf28cfadc69d9ca0c2abbf93191
Distribution notes
- Red Hat Enterprise Linux: https://access.redhat.com/solutions/3001781 https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-10229
- SUSE Enterprise Linux: https://www.suse.com/security/cve/CVE-2016-10229/
- Debian: https://security-tracker.debian.org/tracker/CVE-2016-10229
- Ubuntu: https://people.canonical.com/~ubuntu-security/cve/2016/CVE-2016-10229.html
- Arch: https://security.archlinux.org/CVE-2016-10229
- Android: https://source.android.com/security/bulletin/2017-04-01
Last modified 7 years ago
Last modified on 04/22/17 19:01:24