PT-2006-4343 · Linux+1 · Linux Kernel+3

James Mckenzie

·

Published

2006-07-18

·

Updated

2018-10-30

·

CVE-2006-3468

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions 2.6.x
Description The issue allows remote attackers to cause a denial of service, resulting in a file system panic. This occurs when a crafted UDP packet with a V2 lookup procedure specifies a bad file handle, triggering an error that causes an exported directory to be remounted read-only. The attack is possible when both NFS and EXT3 are used.
Recommendations For Linux kernel version 2.6.x, consider restricting access to the NFS service until a fix is available, and avoid using the V2 lookup procedure with untrusted input to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-3468
DSA-1184-2
RHSA-2006:0617
RHSA-2006_0617

Affected Products

Ext3
Linux Kernel
Nfs
Red Hat