Back

HIGH

kernel: ip_frag_reasm() NULL pointer dereference

Published Dec 8, 2009

Description

The ip_frag_reasm function in net/ipv4/ip_fragment.c in the Linux kernel 2.6.32-rc8, and 2.6.29 and later versions before 2.6.32, calls IP_INC_STATS_BH with an incorrect argument, which allows remote attackers to cause a denial of service (NULL pointer dereference and hang) via long IP packets, possibly related to the ip_defrag function.

Affected products

Remediation

Red Hat statement

Not vulnerable. This issue did not affect the versions of the Linux kernel as shipped with Red Hat Enterprise Linux 3, 4, 5 and Red Hat Enterprise MRG as they did not include upstream commit 7c73a6fa that introduced the problem.

Metrics

References (18)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner canonical
Published Dec 8, 2009
Updated Aug 7, 2024
Reserved Apr 15, 2009
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity n/a
Public date n/a