PatchSiren cyber security CVE debrief
CVE-2016-9400 Fedoraproject CVE debrief
This is a critical client-side memory corruption issue in Teeworlds before 0.6.4. A remote server can influence packet processing in CClient::ProcessServerPacket and, according to NVD, write to arbitrary physical memory locations and possibly execute arbitrary code. The vulnerable path is in client packet handling, so the practical exposure is any user connecting to an untrusted or compromised server.
- Vendor
- Fedoraproject
- Product
- Unknown
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-22
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-22
- Advisory updated
- 2026-05-13
Who should care
Teeworlds players and client operators running versions before 0.6.4 should treat this as urgent. Downstream package maintainers and distro security teams should also verify that shipped Teeworlds builds include the upstream fix, including packages identified in the NVD CPE data.
Technical summary
NVD classifies this as CWE-119 and rates it CVSS 3.1 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). The issue is described in engine/client/client.cpp within CClient::ProcessServerPacket, where snap-handling logic can be driven by a remote server into arbitrary physical memory writes and possible code execution. The affected upstream range is Teeworlds before 0.6.4; NVD also lists Fedora 23 CPE coverage in its vulnerable configuration data.
Defensive priority
Immediate
Recommended defensive actions
- Upgrade Teeworlds to version 0.6.4 or later.
- If you maintain an older branch, backport the upstream fix from commit ff254722a2683867fcb3e67569ffd36226c4bc62.
- Verify downstream packages and images are rebuilt with the fix, especially where Teeworlds was shipped by distributions.
- Treat pre-0.6.4 clients as vulnerable when connecting to untrusted or compromised servers.
- If an immediate upgrade is not possible, reduce exposure by limiting use of affected clients until patched.
Evidence notes
The NVD description states that CClient::ProcessServerPacket in engine/client/client.cpp allows remote servers to write to arbitrary physical memory locations and possibly execute arbitrary code via snap-handling vectors. The record lists CWE-119 and CVSS 3.1 9.8. Supporting references in the corpus include November 2016 oss-security mailing-list posts, an upstream GitHub fix commit, a Teeworlds vendor advisory, and downstream Fedora and Gentoo advisories.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-9400 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-9400
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-9400 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-9400
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/teeworlds/teeworlds/commit/ff254722a2683867fcb3e67569ffd36226c4bc62
[email protected] - Issue Tracking, Patch, Third Party Advisory
-
Source reference
Unverified legacy reference
URL: https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/C4JNSBXXPE7O32ZMFK7D7YL6EKLG7PRV/
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://security.gentoo.org/glsa/201705-13
[email protected] - Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.