The udp6_ufo_fragment function in net/ipv6/udp.c in the Linux kernel before 2.6.39, when a certain UDP Fragmentation Offload (UFO) configuration is enabled, allows remote attackers to cause a denial of service (system crash) by sending fragmented IPv6 UDP packets to a bridge device.
| Software | From | Fixed in |
|---|---|---|
| linux / linux_kernel | - | 2.6.39 |
| avaya / 96x1_ip_deskphone_firmware | 6.0.0 | 6.6.0.x |