CVE-2009-1298

The ip_frag_reasm function in net/ipv4/ip_fragment.c in the Linux kernel 2.6.32-rc8, and 2.6.29 and later versions before 2.6.32, calls IP_INC_STATS_BH with an incorrect argument, which allows remote attackers to cause a denial of service (NULL pointer dereference and hang) via long IP packets, possibly related to the ip_defrag function.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.8 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:N/I:N/A:C
canonicalCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 83%
VendorProductVersion
linuxlinux_kernel
𝑥
≤ 2.6.32
linuxlinux_kernel
2.6.28
linuxlinux_kernel
2.6.28:rc1
linuxlinux_kernel
2.6.28:rc2
linuxlinux_kernel
2.6.28:rc3
linuxlinux_kernel
2.6.28:rc4
linuxlinux_kernel
2.6.28:rc5
linuxlinux_kernel
2.6.28:rc6
linuxlinux_kernel
2.6.28:rc7
linuxlinux_kernel
2.6.28.1
linuxlinux_kernel
2.6.28.2
linuxlinux_kernel
2.6.28.3
linuxlinux_kernel
2.6.28.4
linuxlinux_kernel
2.6.28.5
linuxlinux_kernel
2.6.28.6
linuxlinux_kernel
2.6.28.7
linuxlinux_kernel
2.6.28.8
linuxlinux_kernel
2.6.28.9
linuxlinux_kernel
2.6.28.10
linuxlinux_kernel
2.6.29
linuxlinux_kernel
2.6.29:rc2
linuxlinux_kernel
2.6.29:rc2_git7
linuxlinux_kernel
2.6.29:rc8-kk
linuxlinux_kernel
2.6.29.1
linuxlinux_kernel
2.6.29.2
linuxlinux_kernel
2.6.29.3
linuxlinux_kernel
2.6.29.4
linuxlinux_kernel
2.6.29.5
linuxlinux_kernel
2.6.29.6
linuxlinux_kernel
2.6.30
linuxlinux_kernel
2.6.30:rc1
linuxlinux_kernel
2.6.30:rc2
linuxlinux_kernel
2.6.30:rc3
linuxlinux_kernel
2.6.30:rc4
linuxlinux_kernel
2.6.30:rc5
linuxlinux_kernel
2.6.30:rc6
linuxlinux_kernel
2.6.30:rc7-git6
linuxlinux_kernel
2.6.30.1
linuxlinux_kernel
2.6.30.2
linuxlinux_kernel
2.6.30.3
linuxlinux_kernel
2.6.30.4
linuxlinux_kernel
2.6.30.5
linuxlinux_kernel
2.6.30.6
linuxlinux_kernel
2.6.30.7
linuxlinux_kernel
2.6.30.8
linuxlinux_kernel
2.6.30.9
linuxlinux_kernel
2.6.31
linuxlinux_kernel
2.6.31:rc1
linuxlinux_kernel
2.6.31:rc2
linuxlinux_kernel
2.6.31:rc3
linuxlinux_kernel
2.6.31:rc4
linuxlinux_kernel
2.6.31:rc5
linuxlinux_kernel
2.6.31:rc6
linuxlinux_kernel
2.6.31:rc7
linuxlinux_kernel
2.6.31:rc8
linuxlinux_kernel
2.6.31.1
linuxlinux_kernel
2.6.31.2
linuxlinux_kernel
2.6.31.3
linuxlinux_kernel
2.6.31.4
linuxlinux_kernel
2.6.31.5
linuxlinux_kernel
2.6.31.6
linuxlinux_kernel
2.6.32
linuxlinux_kernel
2.6.32:rc1
linuxlinux_kernel
2.6.32:rc3
linuxlinux_kernel
2.6.32:rc4
linuxlinux_kernel
2.6.32:rc5
linuxlinux_kernel
2.6.32:rc6
linuxlinux_kernel
2.6.32:rc7
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
linux
karmic
Fixed 2.6.31-16.53
released
jaunty
not-affected
intrepid
not-affected
hardy
not-affected
dapper
dne
linux-source-2.6.15
karmic
dne
jaunty
dne
intrepid
dne
hardy
dne
dapper
not-affected
References