Back

MEDIUM

kernel: ipv6: panic using raw sockets

Published Jun 16, 2012

Description

Double free vulnerability in the xfrm6_tunnel_rcv function in net/ipv6/xfrm6_tunnel.c in the Linux kernel before 2.6.22, when the xfrm6_tunnel module is enabled, allows remote attackers to cause a denial of service (panic) via crafted IPv6 packets.

Affected products

Remediation

Red Hat statement

This issue did not affect the Linux kernel as shipped with Red Hat Enterprise Linux 6, and Red Hat Enterprise MRG. This has been addressed in Red Hat Enterprise Linux 5 via https://rhn.redhat.com/errata/RHSA-2012-0480.html. A future kernel update for Red Hat Enterprise Linux 4 may address this issue.

Metrics

Weaknesses (2)

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jun 16, 2012
Updated Aug 6, 2024
Reserved Mar 12, 2012
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Apr 17, 2012