A stack-based buffer overflow in the clntudp_call function in sunrpc/clnt_udp.c in the GNU C Library (aka glibc or libc6) allows remote servers to cause a denial of service (crash) or possibly unspecified other impact via a flood of crafted ICMP and UDP packets (CVE-2016-4429).
A similar issue was fixed in lnt_dg_call in src/clnt_dg.c in libtirpc package as part of this update.
Other fixes in this update: