SB2010012701 - Remote denial of service in Linux kernel IPv4
Published: January 27, 2010 Updated: June 4, 2024
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper locking (CVE-ID: CVE-2009-4272)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The
vulnerability exists due to improper locking when handling crafted
packets that force collisions in the IPv4 routing hash table in
net/ipv4/route.c. A remote attacker can send specially crafted packets
to the system and perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- http://www.openwall.com/lists/oss-security/2010/01/20/1
- https://bugzilla.redhat.com/show_bug.cgi?id=545411
- https://rhn.redhat.com/errata/RHSA-2010-0046.html
- http://www.openwall.com/lists/oss-security/2010/01/20/6
- http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.31
- https://rhn.redhat.com/errata/RHSA-2010-0095.html
- http://support.avaya.com/css/P8/documents/100073666
- https://exchange.xforce.ibmcloud.com/vulnerabilities/55808
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7026
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11167
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=73e42897e8e5619eacb787d2ce69be12f47cfc21
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=b6280b47a7a42970d098a3059f4ebe7e55e90d8d