udp.c in the Linux kernel before 4.5 allows remote attackers to execute arbitrary code via UDP traffic that triggers an unsafe second checksum calculation during execution of a recv system call with the MSG_PEEK flag.
[
{
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "net/ipv6/udp.c",
"function": "udpv6_recvmsg"
},
"digest": {
"length": 2788.0,
"function_hash": "175611877078685601933551434725204676986"
},
"id": "CVE-2016-10229-a51ba320",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@197c949e7798fbf28cfadc69d9ca0c2abbf93191",
"signature_type": "Function"
},
{
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "net/ipv6/udp.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"313872854037796202233356292407791596595",
"253553913521860433838656480250767023660",
"298880032537071643337369035059720143464",
"173973845002323202217435433971647177477",
"224420650729920960551170072074597015813",
"135659894476602925989374463428434616416",
"315928219872333941240025148979869056213",
"334932378772006661289698953419900169756",
"18562390367001575321563020729640832729",
"61850924002616660504477149553537826430",
"1839187067622404087638630520782865112"
]
},
"id": "CVE-2016-10229-b5d51035",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@197c949e7798fbf28cfadc69d9ca0c2abbf93191",
"signature_type": "Line"
},
{
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "net/ipv4/udp.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"313872854037796202233356292407791596595",
"266355656316692799968577254093452607932",
"83002326173120520245218324199100107000",
"122791240207384333819270268593832195155",
"58536487288132090107946239217879117653",
"163371877675353954437299736515801037263",
"315928219872333941240025148979869056213",
"334932378772006661289698953419900169756",
"18562390367001575321563020729640832729",
"61850924002616660504477149553537826430",
"1839187067622404087638630520782865112"
]
},
"id": "CVE-2016-10229-e4a9a295",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@197c949e7798fbf28cfadc69d9ca0c2abbf93191",
"signature_type": "Line"
},
{
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "net/ipv4/udp.c",
"function": "udp_recvmsg"
},
"digest": {
"length": 1983.0,
"function_hash": "247466558459327577656081092281682135573"
},
"id": "CVE-2016-10229-ea0f2620",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@197c949e7798fbf28cfadc69d9ca0c2abbf93191",
"signature_type": "Function"
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-10229.json"