PT-2013-4990 · Linux+4 · Linux Kernel+4

Dmitry Vyukov

·

Published

2013-10-10

·

Updated

2023-02-13

·

CVE-2013-4387

CVSS v2.0

6.1

Medium

VectorAV:A/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions through 3.11.4
Description The issue is related to the improper handling of UDP Fragmentation Offload (UFO) processing in the Linux kernel, which can be triggered by network traffic that causes a large response packet. This can lead to a denial of service, resulting in memory corruption and system crash, or potentially have other unspecified impacts.
Recommendations For Linux kernel versions through 3.11.4, update to a version that contains a fix for this issue to prevent potential denial of service and other impacts.

Exploit

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2013-1178
ALT-PU-2014-1422
CESA-2013_1645
CVE-2013-4387
DLA-0015-1
MGASA-2013-0342
MGASA-2013-0343
MGASA-2013-0344
MGASA-2013-0345
MGASA-2013-0346
MGASA-2013-0371
MGASA-2013-0372
MGASA-2013-0373
MGASA-2013-0374
MGASA-2013-0375
RHSA-2013:1490
RHSA-2013:1645
RHSA-2013_1645
RHSA-2014:0284
USN-2019-1
USN-2021-1
USN-2022-1
USN-2024-1
USN-2038-1
USN-2039-1
USN-2041-1
USN-2045-1
USN-2049-1
USN-2050-1
USN-2233-1
USN-2234-1

Affected Products

Alt Linux
Centos
Linux Kernel
Red Hat
Suse