Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Linux IP Fragment Overlap Vulnerability

Linux kernel 2.0.33 is vulnerable to a denial of service attack related to overlapping IP fragments. The bug is not in the handling of them itself, but the action taken when an oversized packet is recieved. A printk function is called containing a variable without any sort of wrapping or protection in function ip_glue. The consequences of this are a serious remote denial of service [ie, reboot of machine].







 

Privacy Statement
Copyright 2009, SecurityFocus