Proxmox affected by CVE-2016-10229?

Michael 2

New Member
May 13, 2014
4
0
1
Is proxmox affected by CVE-2016-10229 ("udp.c in the Linux kernel before 4.5 allows remote attackers to execute arbitrary code via UDP traffic that triggers an unsafe second checksum calculation during execution of a recv system call with the MSG_PEEK flag.") and if so, is there a timeline for a patched kernel?
 
Do you know if the old 2.6.32 kernel used by Proxmox 3.4 is affected by this vulnerability?
 
AFAIK the proxmox kernel is not affected by CVE-2016-10229.

correct, the fix has been part of the upstream 4.5 kernel, and was backported to Ubuntu's 4.4 kernel in February 2016.