PT-2008-1047 · Linux+1 · Linux Kernel+1

Publicado

2008-05-16

·

Atualizado

2018-10-31

·

CVE-2008-2136

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Red Hat Enterprise Linux kernel versions 2.4.9 through 2.4.18 Linux kernel versions prior to 2.4.36.5 Linux kernel versions prior to 2.6.25.3
Description The issue involves multiple vulnerabilities in the Linux kernel of Red Hat Enterprise Linux, which can lead to disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely, potentially causing a denial of service due to memory consumption via network traffic to a Simple Internet Transition (SIT) tunnel interface. The vulnerabilities are related to the management of an skb reference count and the pskb may pull and kfree skb functions.
Recommendations For Red Hat Enterprise Linux kernel versions 2.4.9 through 2.4.18, update to a version later than 2.4.18 to resolve the issue. For Linux kernel versions prior to 2.4.36.5, update to version 2.4.36.5 or later. For Linux kernel versions prior to 2.6.25.3, update to version 2.6.25.3 or later. As a temporary workaround, consider restricting access to the SIT tunnel interface to minimize the risk of exploitation.

Correção

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-06237
BDU:2015-06238
BDU:2015-06242
BDU:2015-06244
BDU:2015-06253
BDU:2015-06254
BDU:2015-06257
BDU:2015-06259
BDU:2015-06268
BDU:2015-06269
BDU:2015-06272
BDU:2015-06273
BDU:2015-06274
CVE-2008-2136
DSA-1588-1
RHSA-2008:0585
RHSA-2008:0607
RHSA-2008:0612
RHSA-2008:0787
RHSA-2008:0973
RHSA-2008_0607
RHSA-2008_0612
RHSA-2009:0001

Produtos afetados

Linux Kernel
Red Hat