Linux kernel before 2.6.15.3 down to 2.6.12, while constructing an ICMP response in icmp_send, does not properly handle when the ip_options_echo function in icmp.c fails, which allows remote attackers to cause a denial of service (crash) via vectors such as (1) record-route and (2) timestamp IP options with the needaddr bit set and a truncated value
Published Feb 7, 2006
5.0
MEDIUMCVSS 2.0
EPSS 3.86%
Description
Linux kernel before 2.6.15.3 down to 2.6.12, while constructing an ICMP response in icmp_send, does not properly handle when the ip_options_echo function in icmp.c fails, which allows remote attackers to cause a denial of service (crash) via vectors such as (1) record-route and (2) timestamp IP options with the needaddr bit set and a truncated value.
Affected products
No data.
- 2.6.12
- 2.6.12
- 2.6.12
- 2.6.12
- 2.6.12
- 2.6.12
- 2.6.12
- 2.6.12.1
- 2.6.12.2
- 2.6.12.3
- 2.6.12.4
- 2.6.12.5
- 2.6.12.6
- 2.6.13
- 2.6.13
- 2.6.13
- 2.6.13
- 2.6.13
- 2.6.13
- 2.6.13
- 2.6.13
- 2.6.13.1
- 2.6.13.2
- 2.6.13.3
- 2.6.13.4
- 2.6.13.5
- 2.6.14
- 2.6.14
- 2.6.14
- 2.6.14
- 2.6.14
- 2.6.14
- 2.6.14.1
- 2.6.14.2
- 2.6.14.3
- 2.6.14.4
- 2.6.14.5
- 2.6.14.6
- 2.6.14.7
- 2.6.15
- 2.6.15.1
- 2.6.15.2
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Red Hat statement
Not vulnerable. This vulnerability was introduced into the Linux kernel in version 2.6.12 and therefore does not affect users of Red Hat Enterprise Linux 2.1, 3, or 4.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (12 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 3.86% (0.03864) | 89.86th | v5 (v2026.06.15) |
| Jun 15, 2026 | 3.77% (0.03774) | 88.50th | v5 (v2026.06.15) |
| Mar 2, 2026 | 9.91% (0.09911) | 92.92th | v4 (v2025.03.14) |
| Mar 17, 2025 | 6.37% (0.06371) | 90.31th | v4 (v2025.03.14) |
| Jan 14, 2025 | 20.41% (0.20415) | 96.39th | v3 (v2023.03.01) |
| Dec 17, 2024 | 26.18% (0.26184) | 96.73th | v3 (v2023.03.01) |
| Jul 3, 2023 | 12.74% (0.12743) | 94.69th | v3 (v2023.03.01) |
| Apr 5, 2023 | 9.42% (0.09419) | 93.74th | v3 (v2023.03.01) |
| Mar 7, 2023 | 10.50% (0.10499) | 94.06th | v3 (v2023.03.01) |
| Mar 6, 2023 | 3.78% (0.03779) | 85.48th | v2 (v2022.01.01) |
| Apr 1, 2022 | 3.78% (0.03779) | 84.01th | v2 (v2022.01.01) |
| Feb 4, 2022 | 3.78% (0.03779) | 67.21th | v2 (v2022.01.01) |
References (21)
- http://lists.immunitysec.com/pipermail/dailydave/2006-February/002909.html mailing-listx_refsource_MLISTPatch
- http://marc.info/?l=linux-kernel&m=113927617401569&w=2 mailing-listx_refsource_MLIST
- http://marc.info/?l=linux-kernel&m=113927648820694&w=2 mailing-listx_refsource_MLIST
- http://secunia.com/advisories/18766 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/18774 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/18784 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/18788 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/18861 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.15.3 x_refsource_CONFIRM
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:040 vendor-advisoryx_refsource_MANDRIVA
- http://www.novell.com/linux/security/advisories/2006_06_kernel.html vendor-advisoryx_refsource_SUSEPatchVendor Advisory
- http://www.redhat.com/archives/fedora-announce-list/2006-February/msg00037.html vendor-advisoryx_refsource_FEDORAPatchVendor Advisory
- http://www.securityfocus.com/archive/1/427981/100/0/threaded vendor-advisoryx_refsource_FEDORA
- http://www.securityfocus.com/bid/16532 vdb-entryx_refsource_BIDPatch
- http://www.trustix.org/errata/2006/0006 vendor-advisoryx_refsource_TRUSTIXVendor Advisory
- http://www.ubuntu.com/usn/usn-250-1 vendor-advisoryx_refsource_UBUNTU
- http://www.vupen.com/english/advisories/2006/0464 vdb-entryx_refsource_VUPENVendor Advisory
- https://access.redhat.com/security/cve/CVE-2006-0454 Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24575 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2006-0454
- https://www.cve.org/CVERecord?id=CVE-2006-0454
Change history (0)
No recorded changes yet.