Linux kernel before 2.6.15.3 down to 2.6.12, while constructing an ICMP response in icmp_send, does not properly handle when the ip_options_echo function in icmp.c fails, which allows remote attackers to cause a denial of service (crash) via vectors such as (1) record-route and (2) timestamp IP options with the needaddr bit set and a truncated value.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Ubuntu | — | Upgrade linux-image-2.6.12-10-powerpc64-smpUpgrade linux-image-2.6.12-10-powerpcUpgrade linux-image-2.6.12-10-amd64-genericUpgrade linux-image-2.6.12-10-k7Upgrade linux-image-2.6.12-10-itanium-smpUpgrade linux-image-2.6.12-10-mckinley-smpUpgrade linux-patch-ubuntu-2.6.12Upgrade linux-image-2.6.12-10-mckinleyUpgrade linux-image-2.6.12-10-amd64-k8-smp | Nov 8, 2024 | Feb 7, 2006 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub