Back to search
CVE-2017-9074
Published: May 19, 2017
Modified: Aug 5, 2024
PUBLISHED
Description
The IPv6 fragmentation implementation in the Linux kernel through 4.11.1 does not consider that the nexthdr field may be associated with an invalid option, which allows local users to cause a denial of service (out-of-bounds read and BUG) or possibly have unspecified other impact via crafted socket and send system calls.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
98577
vdb-entry
x_refsource_BID
https://patchwork.ozlabs.org/patch/763117/
x_refsource_CONFIRM
RHSA-2018:0169
vendor-advisory
x_refsource_REDHAT
RHSA-2017:2669
vendor-advisory
x_refsource_REDHAT
RHSA-2017:2077
vendor-advisory
x_refsource_REDHAT
DSA-3886
vendor-advisory
x_refsource_DEBIAN
RHSA-2017:1842
vendor-advisory
x_refsource_REDHAT
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now