Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-3535

Опубликовано: 09 сент. 2014
Источник: redhat
CVSS2: 5.4
EPSS Низкий

Описание

include/linux/netdevice.h in the Linux kernel before 2.6.36 incorrectly uses macros for netdev_printk and its related logging implementation, which allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) by sending invalid packets to a VxLAN interface.

A NULL pointer dereference flaw was found in the way the Linux kernel's networking implementation handled logging while processing certain invalid packets coming in via a VxLAN interface. A remote attacker could use this flaw to crash the system by sending a specially crafted packet to such an interface.

Отчет

This issue does not affect the versions of the kernel package as shipped with Red Hat Enterprise Linux 5, 7 and Red Hat Enterprise MRG 2. This issue affects the version of Linux kernel as shipped with Red Hat Enterprise Linux 6. Future kernel updates for Red Hat Enterprise Linux 6 may address this issue.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kernelNot affected
Red Hat Enterprise Linux 7kernelNot affected
Red Hat Enterprise MRG 2realtime-kernelNot affected
Red Hat Enterprise Linux 6kernelFixedRHSA-2014:116709.09.2014
RHEV 3.X Hypervisor and Agents for RHEL-6rhev-hypervisor6FixedRHSA-2014:116809.09.2014

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-228->CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=1114540Kernel: netdevice.h: NULL pointer dereference over VxLAN

EPSS

Процентиль: 73%
0.00821
Низкий

5.4 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 11 лет назад

include/linux/netdevice.h in the Linux kernel before 2.6.36 incorrectly uses macros for netdev_printk and its related logging implementation, which allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) by sending invalid packets to a VxLAN interface.

nvd
почти 11 лет назад

include/linux/netdevice.h in the Linux kernel before 2.6.36 incorrectly uses macros for netdev_printk and its related logging implementation, which allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) by sending invalid packets to a VxLAN interface.

debian
почти 11 лет назад

include/linux/netdevice.h in the Linux kernel before 2.6.36 incorrectl ...

github
около 3 лет назад

include/linux/netdevice.h in the Linux kernel before 2.6.36 incorrectly uses macros for netdev_printk and its related logging implementation, which allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) by sending invalid packets to a VxLAN interface.

oracle-oval
почти 11 лет назад

ELSA-2014-3086: Unbreakable Enterprise kernel security update (IMPORTANT)

EPSS

Процентиль: 73%
0.00821
Низкий

5.4 Medium

CVSS2