kernel: ipv6: skb is unexpectedly freed
Published Mar 31, 2010
7.1
HIGHCVSS 2.0
EPSS 3.29%
Description
Use-after-free vulnerability in net/ipv4/tcp_input.c in the Linux kernel 2.6 before 2.6.20, when IPV6_RECVPKTINFO is set on a listening socket, allows remote attackers to cause a denial of service (kernel panic) via a SYN packet while the socket is in a listening (TCP_LISTEN) state, which is not properly handled and causes the skb structure to be freed.
Affected products
No data.
- 2.6.0
- 2.6.1
- 2.6.2
- 2.6.10
- 2.6.11
- 2.6.11.1
- 2.6.11.2
- 2.6.11.3
- 2.6.11.4
- 2.6.11.5
- 2.6.11.6
- 2.6.11.7
- 2.6.11.8
- 2.6.11.9
- 2.6.11.10
- 2.6.11.11
- 2.6.11.12
- 2.6.12
- 2.6.12.1
- 2.6.12.2
- 2.6.12.3
- 2.6.12.4
- 2.6.12.5
- 2.6.12.6
- 2.6.13
- 2.6.13.1
- 2.6.13.2
- 2.6.13.3
- 2.6.13.4
- 2.6.13.5
- 2.6.14
- 2.6.14.1
- 2.6.14.2
- 2.6.14.3
- 2.6.14.4
- 2.6.14.5
- 2.6.14.6
- 2.6.14.7
- 2.6.15
- 2.6.15.1
- 2.6.15.2
- 2.6.15.3
- 2.6.15.4
- 2.6.15.5
- 2.6.15.6
- 2.6.15.7
- 2.6.16
- 2.6.16.1
- 2.6.16.2
- 2.6.16.3
- 2.6.16.4
- 2.6.16.5
- 2.6.16.6
- 2.6.16.7
- 2.6.16.8
- 2.6.16.9
- 2.6.16.10
- 2.6.16.11
- 2.6.16.12
- 2.6.16.13
- 2.6.16.14
- 2.6.16.15
- 2.6.16.16
- 2.6.16.17
- 2.6.16.18
- 2.6.16.19
- 2.6.16.20
- 2.6.16.21
- 2.6.16.22
- 2.6.16.23
- 2.6.16.24
- 2.6.16.25
- 2.6.16.26
- 2.6.16.27
- 2.6.16.28
- 2.6.16.29
- 2.6.16.30
- 2.6.16.31
- 2.6.16.32
- 2.6.16.33
- 2.6.16.34
- 2.6.16.35
- 2.6.16.36
- 2.6.16.37
- 2.6.16.38
- 2.6.16.39
- 2.6.16.40
- 2.6.16.41
- 2.6.16.42
- 2.6.16.43
- 2.6.16.44
- 2.6.16.45
- 2.6.16.46
- 2.6.16.47
- 2.6.16.48
- 2.6.16.49
- 2.6.16.50
- 2.6.16.51
- 2.6.16.52
- 2.6.16.53
- 2.6.16.54
- 2.6.16.55
- 2.6.16.56
- 2.6.16.57
- 2.6.16.58
- 2.6.16.59
- 2.6.16.60
- 2.6.16.61
- 2.6.16.62
- 2.6.17
- 2.6.17
- 2.6.17
- 2.6.17
- 2.6.17
- 2.6.17
- 2.6.17
- 2.6.17.1
- 2.6.17.2
- 2.6.17.3
- 2.6.17.4
- 2.6.17.5
- 2.6.17.6
- 2.6.17.7
- 2.6.17.8
- 2.6.17.9
- 2.6.17.10
- 2.6.17.11
- 2.6.17.12
- 2.6.17.13
- 2.6.17.14
- 2.6.18
- 2.6.18
- 2.6.18
- 2.6.18
- 2.6.18
- 2.6.18
- 2.6.18
- 2.6.18
- 2.6.18.1
- 2.6.18.2
- 2.6.18.3
- 2.6.18.4
- 2.6.18.5
- 2.6.18.6
- 2.6.18.7
- 2.6.18.8
- 2.6.19
- 2.6.19.1
- 2.6.19.2
- 2.6.19.3
- 2.6.19.4
- 2.6.19.5
- 2.6.19.6
- 2.6.19.7
No data.
Red Hat Enterprise Linux 3 Extended Lifecycle Support
kernel-0:2.4.21-66.EL
Fixed · RHSA-2010:0882
Red Hat Enterprise Linux 4
kernel-0:2.6.9-89.0.25.EL
Fixed · RHSA-2010:0394
Red Hat Enterprise Linux 4.7 Z Stream
kernel-0:2.6.9-78.0.31.EL
Fixed · RHSA-2010:0424
Red Hat Enterprise Linux 5
kernel-0:2.6.18-194.el5
Fixed · RHSA-2010:0178
Red Hat Enterprise Linux 5.3.Z - Server Only
kernel-0:2.6.18-128.17.1.el5
Fixed · RHSA-2010:0439
Red Hat Enterprise Linux 5.4.Z - Server Only
kernel-0:2.6.18-164.17.1.el5
Fixed · RHSA-2010:0380
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 3 Extended Lifecycle Support | kernel-0:2.4.21-66.EL | Fixed | RHSA-2010:0882 |
| Red Hat Enterprise Linux 4 | kernel-0:2.6.9-89.0.25.EL | Fixed | RHSA-2010:0394 |
| Red Hat Enterprise Linux 4.7 Z Stream | kernel-0:2.6.9-78.0.31.EL | Fixed | RHSA-2010:0424 |
| Red Hat Enterprise Linux 5 | kernel-0:2.6.18-194.el5 | Fixed | RHSA-2010:0178 |
| Red Hat Enterprise Linux 5.3.Z - Server Only | kernel-0:2.6.18-128.17.1.el5 | Fixed | RHSA-2010:0439 |
| Red Hat Enterprise Linux 5.4.Z - Server Only | kernel-0:2.6.18-164.17.1.el5 | Fixed | RHSA-2010:0380 |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue did not affect the version of the Linux kernel as shipped with Red Hat Enterprise MRG, as it was fixed since version v2.6.20-rc6.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:N/I:N/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (10 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 3.29% (0.03295) | 88.10th | v5 (v2026.06.15) |
| Jun 15, 2026 | 3.28% (0.03280) | 86.79th | v5 (v2026.06.15) |
| Mar 30, 2025 | 3.63% (0.03629) | 86.72th | v4 (v2025.03.14) |
| Mar 29, 2025 | 2.55% (0.02548) | 75.75th | v4 (v2025.03.14) |
| Mar 17, 2025 | 3.63% (0.03629) | 87.03th | v4 (v2025.03.14) |
| Dec 19, 2024 | 2.48% (0.02485) | 89.78th | v3 (v2023.03.01) |
| Mar 7, 2023 | 4.85% (0.04848) | 91.47th | v3 (v2023.03.01) |
| Mar 6, 2023 | 3.78% (0.03779) | 85.48th | v2 (v2022.01.01) |
| Apr 1, 2022 | 3.78% (0.03779) | 84.01th | v2 (v2022.01.01) |
| Feb 4, 2022 | 3.78% (0.03779) | 67.21th | v2 (v2022.01.01) |
References (18)
- http://git.kernel.org/linus/fb7e2399ec17f1004c0e0ccfd17439f8759ede01 x_refsource_CONFIRMPatch
- http://secunia.com/advisories/39652 third-party-advisoryx_refsource_SECUNIA
- http://support.avaya.com/css/P8/documents/100090459 x_refsource_CONFIRM
- http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.20 x_refsource_CONFIRM
- http://www.openwall.com/lists/oss-security/2010/03/29/1 mailing-listx_refsource_MLIST
- http://www.redhat.com/support/errata/RHSA-2010-0380.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2010-0394.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2010-0424.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2010-0439.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2010-0882.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/bid/39016 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id?1023992 vdb-entryx_refsource_SECTRACK
- http://www.vmware.com/security/advisories/VMSA-2011-0009.html x_refsource_CONFIRM
- https://access.redhat.com/security/cve/CVE-2010-1188 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=577711 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2010-1188
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9878 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2010-1188
Change history (0)
No recorded changes yet.