CVE-2010-4805
26.05.2011, 16:55
The socket implementation in net/core/sock.c in the Linux kernel before 2.6.35 does not properly manage a backlog of received packets, which allows remote attackers to cause a denial of service by sending a large amount of network traffic, related to the sk_add_backlog function and the sk_rmem_alloc socket field. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-4251.Enginsight
Vendor | Product | Version |
---|---|---|
linux | linux_kernel | 𝑥 < 2.6.35 |
redhat | enterprise_linux | 4.0 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
linux |
| ||||||||||||||||||
linux-armadaxp |
| ||||||||||||||||||
linux-ec2 |
| ||||||||||||||||||
linux-fsl-imx51 |
| ||||||||||||||||||
linux-lts-backport-maverick |
| ||||||||||||||||||
linux-lts-backport-natty |
| ||||||||||||||||||
linux-lts-backport-oneiric |
| ||||||||||||||||||
linux-lts-quantal |
| ||||||||||||||||||
linux-lts-raring |
| ||||||||||||||||||
linux-mvl-dove |
| ||||||||||||||||||
linux-source-2.6.15 |
| ||||||||||||||||||
linux-ti-omap4 |
|
References