Linux Kernel RTO (Retransmission Timeouts) Remote Denial of Service Vulnerability
BID:38355
Info
Linux Kernel RTO (Retransmission Timeouts) Remote Denial of Service Vulnerability
| Bugtraq ID: | 38355 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 22 2010 12:00AM |
| Updated: | Feb 22 2010 10:22PM |
| Credit: | Denys Fedoryshchenko |
| Vulnerable: |
Linux kernel 2.6.32 Linux kernel 2.6.32.8 Linux kernel 2.6.32.4 Linux kernel 2.6.32.3 Linux kernel 2.6.32-rc8 Linux kernel 2.6.32-rc7 Linux kernel 2.6.32-rc5 Linux kernel 2.6.32-rc4 Linux kernel 2.6.32-rc3 Linux kernel 2.6.32-rc2 Linux kernel 2.6.32-rc1 |
| Not Vulnerable: | |
Discussion
Linux Kernel RTO (Retransmission Timeouts) Remote Denial of Service Vulnerability
The Linux kernel is prone to a remote denial-of-service vulnerability.
Attackers can exploit this issue to cause an excessive load on CPU and network resources, denying service to legitimate users.
The Linux kernel is prone to a remote denial-of-service vulnerability.
Attackers can exploit this issue to cause an excessive load on CPU and network resources, denying service to legitimate users.
Exploit / POC
Linux Kernel RTO (Retransmission Timeouts) Remote Denial of Service Vulnerability
Attackers can use readily available network utilities to exploit this issue.
Attackers can use readily available network utilities to exploit this issue.
Solution / Fix
Linux Kernel RTO (Retransmission Timeouts) Remote Denial of Service Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Linux Kernel RTO (Retransmission Timeouts) Remote Denial of Service Vulnerability
References:
References:
- Linux kernel Homepage (kernel.org)
- tcp: fix ICMP-RTO war (Damian Lukowski)