conntrackd in conntrack-tools 1.4.2 and earlier does not ensure that the optional kernel modules are loaded before using them, which allows remote attackers to cause a denial of service (crash) via a (1) DCCP, (2) SCTP, or (3) ICMPv6 packet.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade conntrack-tools. | Aug 30, 2017 | Aug 24, 2015 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Mar 24, 2014 |
| Suse | — | Upgrade libnetfilter_cttimeout-develUpgrade libnetfilter_cttimeout1Upgrade conntrackdUpgrade libnetfilter_cthelper-develUpgrade libnetfilter_cthelper0Upgrade conntrack-tools | Dec 18, 2015 | Aug 24, 2015 |
| Ubuntu | — | Upgrade conntrack | Nov 19, 2024 | Aug 24, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub