kernel: ipv6_hop_jumbo remote system crash
Published Dec 21, 2007
7.8
HIGHCVSS 2.0
EPSS 14.34%
Description
The ipv6_hop_jumbo function in net/ipv6/exthdrs.c in the Linux kernel before 2.6.22 does not properly validate the hop-by-hop IPv6 extended header, which allows remote attackers to cause a denial of service (NULL pointer dereference and kernel panic) via a crafted IPv6 packet.
Affected products
No data.
- ≤ 2.6.21.7
- 2.2.27
- 2.4.36
- 2.4.36.1
- 2.4.36.2
- 2.4.36.3
- 2.4.36.4
- 2.4.36.5
- 2.4.36.6
- 2.6
- 2.6.18
- 2.6.18
- 2.6.18
- 2.6.18
- 2.6.18
- 2.6.18
- 2.6.18
- 2.6.18
- 2.6.19.4
- 2.6.19.5
- 2.6.19.6
- 2.6.19.7
- 2.6.20.16
- 2.6.20.17
- 2.6.20.18
- 2.6.20.19
- 2.6.20.20
- 2.6.20.21
- 2.6.21.5
- 2.6.21.6
No data.
Red Hat Enterprise Linux 5
kernel-0:2.6.18-164.10.1.el5
Fixed · RHSA-2010:0019
Red Hat Enterprise Linux 5.2 Z Stream
kernel-0:2.6.18-92.1.35.el5
Fixed · RHSA-2010:0079
Red Hat Enterprise Linux 5.3.Z - Server Only
kernel-0:2.6.18-128.12.1.el5
Fixed · RHSA-2010:0053
Red Hat Enterprise Virtualization for RHEL-5
rhev-hypervisor-0:5.4-2.1.8.el5_4rhev2_1
Fixed · RHSA-2010:0095
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | kernel-0:2.6.18-164.10.1.el5 | Fixed | RHSA-2010:0019 |
| Red Hat Enterprise Linux 5.2 Z Stream | kernel-0:2.6.18-92.1.35.el5 | Fixed | RHSA-2010:0079 |
| Red Hat Enterprise Linux 5.3.Z - Server Only | kernel-0:2.6.18-128.12.1.el5 | Fixed | RHSA-2010:0053 |
| Red Hat Enterprise Virtualization for RHEL-5 | rhev-hypervisor-0:5.4-2.1.8.el5_4rhev2_1 | Fixed | RHSA-2010:0095 |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue did not affect the versions of the Linux kernel as shipped with Red Hat Enterprise Linux 3, 4 and Red Hat Enterprise MRG. Shipped kernels do not include upstream commit a11d206d that introduced the problem. This upstream commit was backported in Red Hat Enterprise Linux 5 via RHBA-2008:0314. It was reported and addressed in Red Hat Enterprise Linux 5 via RHSA-2010:0019.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:N/I:N/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (17 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 14.34% (0.14336) | 96.51th | v5 (v2026.06.15) |
| Jun 15, 2026 | 14.34% (0.14336) | 96.15th | v5 (v2026.06.15) |
| Jun 8, 2026 | 7.22% (0.07216) | 91.77th | v4 (v2025.03.14) |
| Mar 30, 2025 | 5.51% (0.05515) | 89.27th | v4 (v2025.03.14) |
| Mar 29, 2025 | 8.24% (0.08239) | 86.78th | v4 (v2025.03.14) |
| Mar 17, 2025 | 6.30% (0.06298) | 90.24th | v4 (v2025.03.14) |
| Jan 8, 2025 | 14.84% (0.14837) | 95.80th | v3 (v2023.03.01) |
| Dec 17, 2024 | 17.57% (0.17565) | 96.10th | v3 (v2023.03.01) |
| Oct 24, 2024 | 13.69% (0.13689) | 95.76th | v3 (v2023.03.01) |
| Sep 16, 2024 | 8.27% (0.08269) | 94.50th | v3 (v2023.03.01) |
| May 24, 2024 | 7.22% (0.07216) | 94.02th | v3 (v2023.03.01) |
| Aug 5, 2023 | 7.02% (0.07020) | 93.05th | v3 (v2023.03.01) |
| Jun 30, 2023 | 7.35% (0.07347) | 93.11th | v3 (v2023.03.01) |
| Mar 7, 2023 | 7.65% (0.07651) | 93.09th | v3 (v2023.03.01) |
| Mar 6, 2023 | 12.57% (0.12567) | 95.52th | v2 (v2022.01.01) |
| Apr 1, 2022 | 12.57% (0.12567) | 95.18th | v2 (v2022.01.01) |
| Feb 4, 2022 | 12.57% (0.12567) | 90.03th | v2 (v2022.01.01) |
References (19)
- http://bugzilla.kernel.org/show_bug.cgi?id=8450 x_refsource_CONFIRM
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=e76b2b2567b83448c2ee85a896433b96150c92e6 x_refsource_CONFIRM
- http://secunia.com/advisories/25505 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/28170 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/28706 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/38015 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2010-0019.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2010-0053.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/bid/26943 vdb-entryx_refsource_BID
- http://www.ubuntu.com/usn/usn-574-1 vendor-advisoryx_refsource_UBUNTU
- https://access.redhat.com/security/cve/CVE-2007-4567 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=548641 x_refsource_CONFIRMIssue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39171 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2007-4567
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11083 vdb-entrysignaturex_refsource_OVAL
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7474 vdb-entrysignaturex_refsource_OVAL
- https://rhn.redhat.com/errata/RHSA-2010-0095.html vendor-advisoryx_refsource_REDHAT
- https://usn.ubuntu.com/558-1/ vendor-advisoryx_refsource_UBUNTU
- https://www.cve.org/CVERecord?id=CVE-2007-4567
Change history (0)
No recorded changes yet.