The decode_choice function in net/netfilter/nf_conntrack_h323_asn1.c in the Linux kernel before 2.6.20.15, 2.6.21.x before 2.6.21.6, and before 2.6.22 allows remote attackers to cause a denial of service (crash) via an encoded, out-of-range index value for a choice field, which triggers a NULL pointer dereference.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Ubuntu | — | Upgrade linux-image-2.6.20-16-serverUpgrade linux-image-2.6.20-16-sparc64Upgrade linux-image-2.6.20-16-sparc64-smpUpgrade linux-image-2.6.20-16-itaniumUpgrade linux-image-2.6.20-16-386Upgrade linux-image-2.6.20-16-server-bigironUpgrade linux-image-2.6.20-16-powerpc64-smpUpgrade linux-image-2.6.20-16-powerpc-smpUpgrade linux-image-2.6.20-16-hppa32Upgrade linux-image-2.6.20-16-mckinleyUpgrade linux-image-2.6.20-16-powerpcUpgrade linux-image-2.6.20-16-genericUpgrade linux-image-2.6.20-16-hppa64Upgrade linux-image-2.6.20-16-lowlatency | Nov 8, 2024 | Jul 10, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub