PT-2018-7150 · Linux+1 · Linux Kernel+1

Published

2017-02-24

·

Updated

2023-02-12

·

CVE-2017-2634

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions: Linux kernel versions prior to 2.6.22.17
Description: The Linux kernel's Datagram Congestion Control Protocol (DCCP) implementation contains a flaw that could result in memory corruptions. This issue arises because the IPv4-only inet sk rebuild header() function is used for both IPv4 and IPv6 DCCP connections. A remote attacker could exploit this flaw to crash the system.
Recommendations: For Linux kernel versions prior to 2.6.22.17, update to version 2.6.22.17 or later to resolve the issue. As a temporary workaround, consider restricting access to DCCP connections to minimize the risk of exploitation.

Fix

Buffer Overflow

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-2634
RHSA-2017:0323
RHSA-2017:0346
RHSA-2017:0347
RHSA-2017_0323

Affected Products

Linux Kernel
Red Hat