The tcp_find_option function of the netfilter subsystem in Linux kernel 2.6, when using iptables and TCP options rules, allows remote attackers to cause a denial of service (CPU consumption by infinite loop) via a large option length that produces a negative integer after a casting operation to the char type.
| Software | From | Fixed in |
|---|---|---|
| conectiva / linux | 10 | 10.x |
| suse / suse_linux | 9.0 | 9.0.x |
| suse / suse_linux | 8.2 | 8.2.x |
| suse / suse_linux | 8.0 | 8.0.x |
| linux / linux_kernel | 2.6.0 | 2.6.0.x |
| suse / suse_linux | 9.1 | 9.1.x |
| gentoo / linux | - | - |
| suse / suse_linux | 8.1 | 8.1.x |