The tcp_sacktag_write_queue function in net/ipv4/tcp_input.c in Linux kernel 2.6.21 through 2.6.23.7, and 2.6.24-rc through 2.6.24-rc2, allows remote attackers to cause a denial of service (crash) via crafted ACK responses that trigger a NULL pointer dereference.
| Software | From | Fixed in |
|---|---|---|
| linux / linux_kernel | 2.6.21-rc2 | 2.6.21-rc2.x |
| linux / linux_kernel | 2.6.23.4 | 2.6.23.4.x |
| linux / linux_kernel | 2.6.22.15 | 2.6.22.15.x |
| linux / linux_kernel | 2.6.21 | 2.6.21.x |
| linux / linux_kernel | 2.6.22-rc4 | 2.6.22-rc4.x |
| linux / linux_kernel | 2.6.22-rc2 | 2.6.22-rc2.x |
| linux / linux_kernel | 2.6.21-rc5 | 2.6.21-rc5.x |
| linux / linux_kernel | 2.6.22.4 | 2.6.22.4.x |
| linux / linux_kernel | 2.6.21-rc7 | 2.6.21-rc7.x |
| linux / linux_kernel | 2.6.21-rc4 | 2.6.21-rc4.x |
| linux / linux_kernel | 2.6.22.21 | 2.6.22.21.x |
| linux / linux_kernel | 2.6.23.7 | 2.6.23.7.x |
| linux / linux_kernel | 2.6.22.12 | 2.6.22.12.x |
| linux / linux_kernel | 2.6.21.6 | 2.6.21.6.x |
| linux / linux_kernel | 2.6.22.1 | 2.6.22.1.x |
| linux / linux_kernel | 2.6.22 | 2.6.22.x |
| linux / linux_kernel | 2.6.23.1 | 2.6.23.1.x |
| linux / linux_kernel | 2.6.23-rc4 | 2.6.23-rc4.x |
| linux / linux_kernel | 2.6.21.1 | 2.6.21.1.x |
| linux / linux_kernel | 2.6.21.4 | 2.6.21.4.x |
| linux / linux_kernel | 2.6.23-rc3 | 2.6.23-rc3.x |
| linux / linux_kernel | 2.6.21.5 | 2.6.21.5.x |
| linux / linux_kernel | 2.6.22.7 | 2.6.22.7.x |
| linux / linux_kernel | 2.6.23-rc8 | 2.6.23-rc8.x |
| linux / linux_kernel | 2.6.24-rc1 | 2.6.24-rc1.x |
| linux / linux_kernel | 2.6.22-rc5 | 2.6.22-rc5.x |
| linux / linux_kernel | 2.6.21-rc6 | 2.6.21-rc6.x |
| linux / linux_kernel | 2.6.22.18 | 2.6.22.18.x |
| linux / linux_kernel | 2.6.22.20 | 2.6.22.20.x |
| linux / linux_kernel | 2.6.23-rc2 | 2.6.23-rc2.x |
| linux / linux_kernel | 2.6.22.6 | 2.6.22.6.x |
| linux / linux_kernel | 2.6.23.3 | 2.6.23.3.x |
| linux / linux_kernel | 2.6.22.3 | 2.6.22.3.x |
| linux / linux_kernel | 2.6.23-rc6 | 2.6.23-rc6.x |
| linux / linux_kernel | 2.6.23-rc1 | 2.6.23-rc1.x |
| linux / linux_kernel | 2.6.22.9 | 2.6.22.9.x |
| linux / linux_kernel | 2.6.22-rc3 | 2.6.22-rc3.x |
| linux / linux_kernel | 2.6.22.13 | 2.6.22.13.x |
| linux / linux_kernel | 2.6.23-rc7 | 2.6.23-rc7.x |
| linux / linux_kernel | 2.6.21.3 | 2.6.21.3.x |
| linux / linux_kernel | 2.6.22.17 | 2.6.22.17.x |
| linux / linux_kernel | 2.6.21-rc1 | 2.6.21-rc1.x |
| linux / linux_kernel | 2.6.22-rc1 | 2.6.22-rc1.x |
| linux / linux_kernel | 2.6.22.11 | 2.6.22.11.x |
| linux / linux_kernel | 2.6.23 | 2.6.23.x |
| linux / linux_kernel | 2.6.22.10 | 2.6.22.10.x |
| linux / linux_kernel | 2.6.23.2 | 2.6.23.2.x |
| linux / linux_kernel | 2.6.21.7 | 2.6.21.7.x |
| linux / linux_kernel | 2.6.21.2 | 2.6.21.2.x |
| linux / linux_kernel | 2.6.24-rc2 | 2.6.24-rc2.x |
| linux / linux_kernel | 2.6.23-rc9 | 2.6.23-rc9.x |
| linux / linux_kernel | 2.6.22.22 | 2.6.22.22.x |
| linux / linux_kernel | 2.6.22-rc7 | 2.6.22-rc7.x |
| linux / linux_kernel | 2.6.23.5 | 2.6.23.5.x |
| linux / linux_kernel | 2.6.22.8 | 2.6.22.8.x |
| linux / linux_kernel | 2.6.23.6 | 2.6.23.6.x |
| linux / linux_kernel | 2.6.22-rc6 | 2.6.22-rc6.x |
| linux / linux_kernel | 2.6.22.2 | 2.6.22.2.x |
| linux / linux_kernel | 2.6.22.19 | 2.6.22.19.x |
| linux / linux_kernel | 2.6.22.5 | 2.6.22.5.x |
| linux / linux_kernel | 2.6.21-rc3 | 2.6.21-rc3.x |
| linux / linux_kernel | 2.6.23-rc5 | 2.6.23-rc5.x |
| linux / linux_kernel | 2.6.22.16 | 2.6.22.16.x |
| linux / linux_kernel | 2.6.22.14 | 2.6.22.14.x |