kernel: iptables restriction bypass if a protocol handler kernel module not loaded
Published Mar 2, 2015
5.0
MEDIUMCVSS 2.0
EPSS 5.49%
Description
net/netfilter/nf_conntrack_proto_generic.c in the Linux kernel before 3.18 generates incorrect conntrack entries during handling of certain iptables rule sets for the SCTP, DCCP, GRE, and UDP-Lite protocols, which allows remote attackers to bypass intended access restrictions via packets with disallowed port numbers.
Affected products
No data.
Configuration 1
- < 3.18
Configuration 2
- 13.1
- 12
- 11
- 11
- 12
- 12
- 12
Configuration 3
- 6.0
- 7.0
- 6.0
- 7.0
- 6.5
- 6.6
- 7.3
- 7.6
- 6.5
- 6.6
- 7.3
- 7.4
- 7.5
- 7.6
- 7.7
- 6.5
- 6.6
- 7.6
- 7.7
- 6.0
- 7.0
Configuration 4
- 7.0
- 8.0
Configuration 5
- 12.04
- 14.04
- 14.10
No data.
Red Hat Enterprise Linux 6
kernel-0:2.6.32-504.12.2.el6
Fixed · RHSA-2015:0674
Red Hat Enterprise Linux 6.5 Extended Update Support
kernel-0:2.6.32-431.50.1.el6
Fixed · RHSA-2015:0284
Red Hat Enterprise Linux 7
kernel-0:3.10.0-229.el7
Fixed · RHSA-2015:0290
Red Hat Enterprise Linux 5
kernel
Under investigation
Red Hat Enterprise Linux 7
kernel-rt
Affected
Red Hat Enterprise MRG 2
kernel
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel-0:2.6.32-504.12.2.el6 | Fixed | RHSA-2015:0674 |
| Red Hat Enterprise Linux 6.5 Extended Update Support | kernel-0:2.6.32-431.50.1.el6 | Fixed | RHSA-2015:0284 |
| Red Hat Enterprise Linux 7 | kernel-0:3.10.0-229.el7 | Fixed | RHSA-2015:0290 |
| Red Hat Enterprise Linux 5 | kernel | Under investigation | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Affected | n/a |
| Red Hat Enterprise MRG 2 | kernel | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:N/I:P/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (9 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 5.49% (0.05489) | 92.53th | v5 (v2026.06.15) |
| Jun 15, 2026 | 5.49% (0.05489) | 91.73th | v5 (v2026.06.15) |
| Mar 17, 2025 | 3.19% (0.03195) | 86.14th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.37% (0.00366) | 73.34th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.36% (0.00356) | 71.26th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.36% (0.00356) | 67.60th | v3 (v2023.03.01) |
| Mar 6, 2023 | 4.36% (0.04358) | 88.02th | v2 (v2022.01.01) |
| Apr 1, 2022 | 4.36% (0.04358) | 86.83th | v2 (v2022.01.01) |
| Feb 4, 2022 | 4.36% (0.04358) | 70.59th | v2 (v2022.01.01) |
References (25)
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=db29a9508a9246e77087c5531e45b2c88ec6988b x_refsource_CONFIRM
- http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00020.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00000.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00009.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00015.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-0284.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-0290.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-0674.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://www.debian.org/security/2015/dsa-3170 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:057 vendor-advisoryx_refsource_MANDRIVAThird Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:058 vendor-advisoryx_refsource_MANDRIVAThird Party Advisory
- http://www.openwall.com/lists/oss-security/2015/01/14/3 mailing-listx_refsource_MLISTMailing ListPatchThird Party Advisory
- http://www.securityfocus.com/bid/72061 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.spinics.net/lists/netfilter-devel/msg33430.html mailing-listx_refsource_MLISTPatchThird Party Advisory
- http://www.ubuntu.com/usn/USN-2513-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- http://www.ubuntu.com/usn/USN-2514-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- http://www.ubuntu.com/usn/USN-2515-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- http://www.ubuntu.com/usn/USN-2516-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- http://www.ubuntu.com/usn/USN-2517-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- http://www.ubuntu.com/usn/USN-2518-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2014-8160 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1182059 x_refsource_CONFIRMIssue TrackingThird Party Advisory
- https://github.com/torvalds/linux/commit/db29a9508a9246e77087c5531e45b2c88ec6988b x_refsource_CONFIRMPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2014-8160
- https://www.cve.org/CVERecord?id=CVE-2014-8160
Change history (0)
No recorded changes yet.