CVE-2010-4805
26.05.2011, 16:55
The socket implementation in net/core/sock.c in the Linux kernel before 2.6.35 does not properly manage a backlog of received packets, which allows remote attackers to cause a denial of service by sending a large amount of network traffic, related to the sk_add_backlog function and the sk_rmem_alloc socket field. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-4251.Enginsight
| Vendor | Product | Version |
|---|---|---|
| linux | linux_kernel | 𝑥 < 2.6.35 |
| redhat | enterprise_linux | 4.0 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux |
| ||||||||||||||||||
| linux-armadaxp |
| ||||||||||||||||||
| linux-ec2 |
| ||||||||||||||||||
| linux-fsl-imx51 |
| ||||||||||||||||||
| linux-lts-backport-maverick |
| ||||||||||||||||||
| linux-lts-backport-natty |
| ||||||||||||||||||
| linux-lts-backport-oneiric |
| ||||||||||||||||||
| linux-lts-quantal |
| ||||||||||||||||||
| linux-lts-raring |
| ||||||||||||||||||
| linux-mvl-dove |
| ||||||||||||||||||
| linux-source-2.6.15 |
| ||||||||||||||||||
| linux-ti-omap4 |
|
References