Back

MEDIUM

Kernel: net: guard tcp_set_keepalive against crash

Published Sep 28, 2014

Description

The sock_setsockopt function in net/core/sock.c in the Linux kernel before 3.5.7 does not ensure that a keepalive action is associated with a stream socket, which allows local users to cause a denial of service (system crash) by leveraging the ability to create a raw socket.

Affected products

Remediation

Red Hat statement

This issue does not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 7 and Red Hat Enterprise MRG 2. This issue affects the version of the kernel package as shipped with Red Hat Enterprise Linux 5 and 6. Future kernel updates for Red Hat Enterprise Linux 5 and 6 may address this issue.

Metrics

Weaknesses (1)

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Sep 28, 2014
Updated Aug 6, 2024
Reserved Sep 15, 2014
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Sep 24, 2012