conntrackd in conntrack-tools 1.4.2 and earlier does not ensure that the optional kernel modules are loaded before using them, which allows remote attackers to cause a denial of service (crash) via a (1) DCCP, (2) SCTP, or (3) ICMPv6 packet.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade conntrack-tools. | Aug 30, 2017 | Aug 24, 2015 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Mar 24, 2014 |
| Suse | — | Upgrade libnetfilter_cttimeout1Upgrade libnetfilter_cttimeout-develUpgrade conntrackdUpgrade conntrack-toolsUpgrade libnetfilter_cthelper-develUpgrade libnetfilter_cthelper0 | Dec 18, 2015 | Aug 24, 2015 |
| Ubuntu | — | Upgrade conntrack | Nov 19, 2024 | Aug 24, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub