Back to search
CVE-2009-1298
Published: Dec 8, 2009
Modified: Aug 7, 2024
PUBLISHED
Description
The ip_frag_reasm function in net/ipv4/ip_fragment.c in the Linux kernel 2.6.32-rc8, and 2.6.29 and later versions before 2.6.32, calls IP_INC_STATS_BH with an incorrect argument, which allows remote attackers to cause a denial of service (NULL pointer dereference and hang) via long IP packets, possibly related to the ip_defrag function.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
http://twitter.com/spendergrsec/statuses/6339560349
x_refsource_MISC
SUSE-SA:2010:001
vendor-advisory
x_refsource_SUSE
MDVSA-2009:329
vendor-advisory
x_refsource_MANDRIVA
USN-869-1
vendor-advisory
x_refsource_UBUNTU
FEDORA-2009-12786
vendor-advisory
x_refsource_FEDORA
http://wiki.rpath.com/Advisories:rPSA-2009-0161
x_refsource_CONFIRM
20091216 rPSA-2009-0161-1 hwdata kernel
mailing-list
x_refsource_BUGTRAQ
37624
third-party-advisory
x_refsource_SECUNIA
FEDORA-2009-12825
vendor-advisory
x_refsource_FEDORA
60788
vdb-entry
x_refsource_OSVDB
https://bugzilla.redhat.com/show_bug.cgi?id=544144
x_refsource_CONFIRM
38017
third-party-advisory
x_refsource_SECUNIA
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.32
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now