kernel: dccp: fix oops on Reset after close
Published Jul 18, 2011
7.8
HIGHCVSS 2.0
EPSS 3.48%
Description
The dccp_rcv_state_process function in net/dccp/input.c in the Datagram Congestion Control Protocol (DCCP) implementation in the Linux kernel before 2.6.38 does not properly handle packets for a CLOSED endpoint, which allows remote attackers to cause a denial of service (NULL pointer dereference and OOPS) by sending a DCCP-Close packet followed by a DCCP-Reset packet.
Affected products
No data.
Configuration 1
- < 2.6.38
Configuration 2
- 5.6
- 5.0
- 5.6
- 5.0
- 5.0
No data.
MRG for RHEL-5
kernel-rt-0:2.6.33.9-rt31.64.el5rt
Fixed · RHSA-2011:0500
Red Hat Enterprise Linux 5
kernel-0:2.6.18-238.12.1.el5
Fixed · RHSA-2011:0833
Red Hat Enterprise Linux 6
kernel-0:2.6.32-71.29.1.el6
Fixed · RHSA-2011:0498
| Product | Package | State | Advisory |
|---|---|---|---|
| MRG for RHEL-5 | kernel-rt-0:2.6.33.9-rt31.64.el5rt | Fixed | RHSA-2011:0500 |
| Red Hat Enterprise Linux 5 | kernel-0:2.6.18-238.12.1.el5 | Fixed | RHSA-2011:0833 |
| Red Hat Enterprise Linux 6 | kernel-0:2.6.32-71.29.1.el6 | Fixed | RHSA-2011:0498 |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue did not affect the version of Linux kernel as shipped with Red Hat Enterprise Linux 4 as it did not include support for the DCCP protocol. Future updates in Red Hat Enterprise Linux 5, 6 and Red Hat Enterprise MRG may address this flaw.
Red Hat mitigation
For users that do not run applications that use DCCP, you can prevent the dccp module from being loaded by adding the following entry to the end of the /etc/modprobe.d/blacklist file: blacklist dccp This way, the dccp module cannot be loaded accidentally, which may occur if an application that requires DCCP is started. A reboot is not necessary for this change to take effect but do make sure the module is not loaded in the first place. You can verify that by running: lsmod | grep dccp You may also consider removing the CAP_SYS_MODULE capability from the current global capability set to prevent kernel modules from being loaded or unloaded. The CAP_SYS_MODULE has a capability number of 16 (see linux/capability.h). The default value has all the bits set. To remove this capability, you have to clear the 16th bit of the default 32-bit value, e.g. 0xffffff ^ (1 << 16): echo 0xFFFEFFFF > /proc/sys/kernel/cap-bound
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:N/I:N/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (11 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 3.48% (0.03477) | 88.71th | v5 (v2026.06.15) |
| Jun 15, 2026 | 3.41% (0.03411) | 87.29th | v5 (v2026.06.15) |
| Mar 17, 2025 | 1.22% (0.01222) | 77.71th | v4 (v2025.03.14) |
| Dec 17, 2024 | 1.46% (0.01455) | 86.41th | v3 (v2023.03.01) |
| Dec 12, 2024 | 2.71% (0.02710) | 90.86th | v3 (v2023.03.01) |
| Mar 7, 2023 | 2.71% (0.02710) | 88.83th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.41% (0.01408) | 72.89th | v2 (v2022.01.01) |
| Feb 13, 2023 | 1.41% (0.01408) | 72.37th | v2 (v2022.01.01) |
| Feb 3, 2023 | 2.17% (0.02172) | 80.18th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.41% (0.01408) | 70.87th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.41% (0.01408) | 49.94th | v2 (v2022.01.01) |
References (11)
- http://downloads.avaya.com/css/P8/documents/100145416 x_refsource_CONFIRMThird Party Advisory
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=720dc34bbbe9493c7bd48b2243058b4e447a929d x_refsource_CONFIRM
- http://openwall.com/lists/oss-security/2011/03/08/19 mailing-listx_refsource_MLISTMailing ListPatchThird Party Advisory
- http://openwall.com/lists/oss-security/2011/03/08/4 mailing-listx_refsource_MLISTMailing ListPatchThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2011-0833.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.38 x_refsource_CONFIRMBroken Link
- http://www.securityfocus.com/bid/46793 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2011-1093 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=682954 x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2011-1093
- https://www.cve.org/CVERecord?id=CVE-2011-1093
Change history (0)
No recorded changes yet.