PT-2004-1718 · Linux+1 · Linux Kernel+2
Published
2004-07-06
·
Updated
2017-07-11
·
CVE-2004-0626
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Linux kernel version 2.6
Description
The issue allows remote attackers to cause a denial of service, specifically CPU consumption by an infinite loop, when using iptables and TCP options rules. This occurs due to a large option length that produces a negative integer after a casting operation to the char type in the
tcp find option function of the netfilter subsystem.Recommendations
For Linux kernel version 2.6, consider applying configuration changes to restrict the use of TCP options rules with iptables to minimize the risk of exploitation. As a temporary workaround, restrict access to the netfilter subsystem until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel
Iptables
Netfilter