Total vulnerabilities in the database
The ip_expire function in net/ipv4/ip_fragment.c in the Linux kernel before 2.6.39 does not properly construct ICMP_TIME_EXCEEDED packets after a timeout, which allows remote attackers to cause a denial of service (invalid pointer dereference) via crafted fragmented packets.
Software | From | Fixed in |
---|---|---|
linux / linux_kernel | 2.6.38-rc7 | 2.6.38-rc7.x |
linux / linux_kernel | 2.6.38-rc6 | 2.6.38-rc6.x |
linux / linux_kernel | 2.6.38-rc4 | 2.6.38-rc4.x |
linux / linux_kernel | 2.6.38.3 | 2.6.38.3.x |
linux / linux_kernel | - | 2.6.38.8.x |
linux / linux_kernel | 2.6.38-rc3 | 2.6.38-rc3.x |
linux / linux_kernel | 2.6.38-rc5 | 2.6.38-rc5.x |
linux / linux_kernel | 2.6.38-rc2 | 2.6.38-rc2.x |
linux / linux_kernel | 2.6.38.6 | 2.6.38.6.x |
linux / linux_kernel | 2.6.38.1 | 2.6.38.1.x |
linux / linux_kernel | 2.6.38-rc1 | 2.6.38-rc1.x |
linux / linux_kernel | 2.6.38.5 | 2.6.38.5.x |
linux / linux_kernel | 2.6.38.2 | 2.6.38.2.x |
linux / linux_kernel | 2.6.38 | 2.6.38.x |
linux / linux_kernel | 2.6.38-rc8 | 2.6.38-rc8.x |
linux / linux_kernel | 2.6.38.4 | 2.6.38.4.x |
linux / linux_kernel | 2.6.38.7 | 2.6.38.7.x |