Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mrx3-23h7-m29p

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью

Описание

net/ipv4/inet_diag.c in the Linux kernel before 2.6.37-rc2 does not properly audit INET_DIAG bytecode, which allows local users to cause a denial of service (kernel infinite loop) via crafted INET_DIAG_REQ_BYTECODE instructions in a netlink message that contains multiple attribute elements, as demonstrated by INET_DIAG_BC_JMP instructions.

net/ipv4/inet_diag.c in the Linux kernel before 2.6.37-rc2 does not properly audit INET_DIAG bytecode, which allows local users to cause a denial of service (kernel infinite loop) via crafted INET_DIAG_REQ_BYTECODE instructions in a netlink message that contains multiple attribute elements, as demonstrated by INET_DIAG_BC_JMP instructions.

EPSS

Процентиль: 33%
0.00127
Низкий

Дефекты

CWE-835

Связанные уязвимости

ubuntu
больше 14 лет назад

net/ipv4/inet_diag.c in the Linux kernel before 2.6.37-rc2 does not properly audit INET_DIAG bytecode, which allows local users to cause a denial of service (kernel infinite loop) via crafted INET_DIAG_REQ_BYTECODE instructions in a netlink message that contains multiple attribute elements, as demonstrated by INET_DIAG_BC_JMP instructions.

redhat
больше 14 лет назад

net/ipv4/inet_diag.c in the Linux kernel before 2.6.37-rc2 does not properly audit INET_DIAG bytecode, which allows local users to cause a denial of service (kernel infinite loop) via crafted INET_DIAG_REQ_BYTECODE instructions in a netlink message that contains multiple attribute elements, as demonstrated by INET_DIAG_BC_JMP instructions.

nvd
больше 14 лет назад

net/ipv4/inet_diag.c in the Linux kernel before 2.6.37-rc2 does not properly audit INET_DIAG bytecode, which allows local users to cause a denial of service (kernel infinite loop) via crafted INET_DIAG_REQ_BYTECODE instructions in a netlink message that contains multiple attribute elements, as demonstrated by INET_DIAG_BC_JMP instructions.

debian
больше 14 лет назад

net/ipv4/inet_diag.c in the Linux kernel before 2.6.37-rc2 does not pr ...

oracle-oval
больше 14 лет назад

ELSA-2011-0004: kernel security, bug fix, and enhancement update (IMPORTANT)

EPSS

Процентиль: 33%
0.00127
Низкий

Дефекты

CWE-835