PT-2004-1718 · Linux+1 · Linux Kernel+2

Published

2004-07-06

·

Updated

2017-07-11

·

CVE-2004-0626

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Linux kernel version 2.6
Description The issue allows remote attackers to cause a denial of service, specifically CPU consumption by an infinite loop, when using iptables and TCP options rules. This occurs due to a large option length that produces a negative integer after a casting operation to the char type in the tcp find option function of the netfilter subsystem.
Recommendations For Linux kernel version 2.6, consider applying configuration changes to restrict the use of TCP options rules with iptables to minimize the risk of exploitation. As a temporary workaround, restrict access to the netfilter subsystem until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-0626

Affected Products

Linux Kernel
Iptables
Netfilter