|
|
|
Vulnerability Note VU#920689Linux Kernel vulnerable to DoS via the ipv6_getsockopt_sticky() functionOverviewThe Linux Kernel contains a vulnerability that may allow a remote attacker to create a denial-of-service condition.I. DescriptionInternet Protocol version 6 (IPv6) is a IP standard that is designed to replace the Internet Protocol version 4 (IPv4). The Linux kernel provides IPv6 support, and Linux vendors may enable IPv6 by default.The Linux kernel contains a condition that may allow a null pointer to be dereferenced during a memory allocation by the ipv6_getsockopt_sticky() function in net/ipv6/ipv6_sockglue.c. Note that this vulnerability may be present in both the 2.4 and 2.6 versions of the Linux kernel.
This issue has been addressed in Linux kernel version 2.6.20.2. Users who do not compile their kernels from source should contact their operating system vendor for updated kernel packages.
References
Thanks to Chris Wright for information that was used in this report. This document was written by Ryan Giobbi.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
||||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||