Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-6214

Опубликовано: 07 фев. 2017
Источник: redhat
CVSS3: 6.5

Описание

The tcp_splice_read function in net/ipv4/tcp.c in the Linux kernel before 4.9.11 allows remote attackers to cause a denial of service (infinite loop and soft lockup) via vectors involving a TCP packet with the URG flag.

A flaw was found in the Linux kernel's handling of packets with the URG flag. Applications using the splice() and tcp_splice_read() functionality could allow a remote attacker to force the kernel to enter a condition in which it could loop indefinitely.

Отчет

This issue does not affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 5 as the code with the flaw is not present in the products listed. This issue affects the Linux kernel packages as shipped with Red Hat Enterprise Linux 6, 7 and MRG-2. Future Linux kernel updates for the respective releases might address this issue.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kernelNot affected
Red Hat Enterprise Linux 6kernelFixedRHSA-2017:137230.05.2017
Red Hat Enterprise Linux 7kernel-rtFixedRHSA-2017:161628.06.2017
Red Hat Enterprise Linux 7kernelFixedRHSA-2017:161528.06.2017
Red Hat Enterprise MRG 2kernel-rtFixedRHSA-2017:164728.06.2017

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-835
https://bugzilla.redhat.com/show_bug.cgi?id=1426542kernel: ipv4/tcp: Infinite loop in tcp_splice_read()

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 8 лет назад

The tcp_splice_read function in net/ipv4/tcp.c in the Linux kernel before 4.9.11 allows remote attackers to cause a denial of service (infinite loop and soft lockup) via vectors involving a TCP packet with the URG flag.

CVSS3: 7.5
nvd
больше 8 лет назад

The tcp_splice_read function in net/ipv4/tcp.c in the Linux kernel before 4.9.11 allows remote attackers to cause a denial of service (infinite loop and soft lockup) via vectors involving a TCP packet with the URG flag.

CVSS3: 7.5
debian
больше 8 лет назад

The tcp_splice_read function in net/ipv4/tcp.c in the Linux kernel bef ...

CVSS3: 7.5
github
около 3 лет назад

The tcp_splice_read function in net/ipv4/tcp.c in the Linux kernel before 4.9.11 allows remote attackers to cause a denial of service (infinite loop and soft lockup) via vectors involving a TCP packet with the URG flag.

oracle-oval
около 8 лет назад

ELSA-2017-1372: kernel security and bug fix update (MODERATE)

6.5 Medium

CVSS3