Proxmox affected by CVE-2016-10229?

Michael 2

New Member
May 13, 2014
4
0
1
Is proxmox affected by CVE-2016-10229 ("udp.c in the Linux kernel before 4.5 allows remote attackers to execute arbitrary code via UDP traffic that triggers an unsafe second checksum calculation during execution of a recv system call with the MSG_PEEK flag.") and if so, is there a timeline for a patched kernel?
 
Do you know if the old 2.6.32 kernel used by Proxmox 3.4 is affected by this vulnerability?
 
AFAIK the proxmox kernel is not affected by CVE-2016-10229.

correct, the fix has been part of the upstream 4.5 kernel, and was backported to Ubuntu's 4.4 kernel in February 2016.
 

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!