Drew DeVault 4/13/2017

MSG_PEEK is pretty common, CVE-2016-10229 is worse than you think

Read Original

The article discusses CVE-2016-10229, a Linux kernel vulnerability allowing arbitrary code execution via UDP if software uses the MSG_PEEK flag. It argues MSG_PEEK is a common, useful feature, listing major software like nginx, curl, and Python that use it. The author urges immediate kernel updates, especially for cloud servers, and notes major distributions may still be vulnerable depending on the kernel version.

MSG_PEEK is pretty common, CVE-2016-10229 is worse than you think

Comments

No comments yet

Be the first to share your thoughts!

Browser Extension

Get instant access to AllDevBlogs from your browser

Top of the Week