Linux Kernel 'icmp_send()' NULL Pointer Dereference Remote Denial of Service Vulnerability
BID:47872
Info
Linux Kernel 'icmp_send()' NULL Pointer Dereference Remote Denial of Service Vulnerability
| Bugtraq ID: | 47872 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2011-1927 |
| Remote: | Yes |
| Local: | No |
| Published: | May 16 2011 12:00AM |
| Updated: | Mar 08 2012 06:10PM |
| Credit: | Aristide Fattori, University degli Studi di Milano and Roberto Paleari, Emaze Networks |
| Vulnerable: |
Ubuntu Ubuntu Linux 11.04 powerpc Ubuntu Ubuntu Linux 11.04 i386 Ubuntu Ubuntu Linux 11.04 ARM Ubuntu Ubuntu Linux 11.04 amd64 Ubuntu Ubuntu Linux 10.10 powerpc Ubuntu Ubuntu Linux 10.10 i386 Ubuntu Ubuntu Linux 10.10 ARM Ubuntu Ubuntu Linux 10.10 amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 Linux kernel 2.6.38.6 Linux kernel 2.6.38.4 Linux kernel 2.6.38.3 |
| Not Vulnerable: | |
Discussion
Linux Kernel 'icmp_send()' NULL Pointer Dereference Remote Denial of Service Vulnerability
The Linux kernel is prone to a remote denial-of-service vulnerability because it fails to properly handle user-supplied input.
Attackers can exploit this issue to cause the affected kernel to crash, denying service to legitimate users. Due to the nature of this issue, arbitrary code execution may be possible, but has not been confirmed.
The Linux kernel is prone to a remote denial-of-service vulnerability because it fails to properly handle user-supplied input.
Attackers can exploit this issue to cause the affected kernel to crash, denying service to legitimate users. Due to the nature of this issue, arbitrary code execution may be possible, but has not been confirmed.
Exploit / POC
Linux Kernel 'icmp_send()' NULL Pointer Dereference Remote Denial of Service Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Linux Kernel 'icmp_send()' NULL Pointer Dereference Remote Denial of Service Vulnerability
References:
References:
- Linux kernel Homepage (kernel.org)
- net: ip_expire() must revalidate route (Eric Dumazet)
- Null pointer dereference in icmp_send (Aristide Fattori)
- Linux Kernel 2.6.38 Remote NULL Pointer Dereference ([email protected])