A certain Debian patch to the IPv6 implementation in the Linux kernel 3.2.x through 3.2.63 does not properly validate arguments in ipv6_select_ident function calls, which allows local users to cause a denial of service (NULL pointer dereference and system crash) by leveraging (1) tun or (2) macvtap device access.
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Jul 30, 2024 | Nov 10, 2014 |
| Ubuntu | — | Upgrade linux-image-3.2.0-72-virtualUpgrade linux-image-3.2.0-72-powerpc-smpUpgrade linux-image-3.2.0-72-highbankUpgrade linux-image-3.2.0-72-generic-paeUpgrade linux-image-3.2.0-72-powerpc64-smpUpgrade linux-image-3.2.0-72-omapUpgrade linux-image-3.2.0-72-genericUpgrade linux-image-3.2.0-1456-omap4 | Nov 8, 2024 | Nov 10, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub