The nfattr_to_tcp function in ip_conntrack_proto_tcp.c in ctnetlink in Linux kernel 2.6.14 up to 2.6.14.3 allows attackers to cause a denial of service (kernel oops) via an update message without private protocol information, which triggers a null dereference.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Linux_kernel | Linux | 2.6.14 (including) | 2.6.14 (including) |
Linux_kernel | Linux | 2.6.14-rc1 (including) | 2.6.14-rc1 (including) |
Linux_kernel | Linux | 2.6.14-rc2 (including) | 2.6.14-rc2 (including) |
Linux_kernel | Linux | 2.6.14-rc3 (including) | 2.6.14-rc3 (including) |
Linux_kernel | Linux | 2.6.14-rc4 (including) | 2.6.14-rc4 (including) |
Linux_kernel | Linux | 2.6.14.1 (including) | 2.6.14.1 (including) |
Linux_kernel | Linux | 2.6.14.2 (including) | 2.6.14.2 (including) |
Linux_kernel | Linux | 2.6.14.3 (including) | 2.6.14.3 (including) |