CVE-2005-3858
Memory leak in the ip6_input_finish function in ip6_input.c in Linux kernel 2.6.12 and earlier might allow attackers to cause a denial of service via malformed IPv6 packets with unspecified parameter problems, which prevents the SKB from being freed.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.29%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Memory leak in the ip6_input_finish function in ip6_input.c in Linux kernel 2.6.12 and earlier might allow attackers to cause a denial of service via malformed IPv6 packets with unspecified parameter problems, which prevents the SKB from being freed.
- CVSS 2.0
- 7.8 HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
- EPSS
- 3.29% probability · 88th percentile
- CISA KEV
- Not listed
- Affected
- linux/linux kernel
- Source
- cve@mitre.org
References
- http://lists.suse.de/archive/suse-security-announce/2006-Feb/0010.html
- http://marc.info/?l=linux-kernel&m=112508479120081&w=2
- http://marc.info/?l=linux-kernel&m=112533899509033&w=2
- http://secunia.com/advisories/18203
- http://secunia.com/advisories/18510
- http://secunia.com/advisories/18562
- http://secunia.com/advisories/19038
- http://secunia.com/advisories/19369
- http://secunia.com/advisories/19374
- http://www.debian.org/security/2006/dsa-1017
- http://www.debian.org/security/2006/dsa-1018
- http://www.redhat.com/support/errata/RHSA-2006-0101.html
- http://www.redhat.com/support/errata/RHSA-2006-0140.html
- http://www.securityfocus.com/bid/16043
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9396
- https://usn.ubuntu.com/231-1/
- http://lists.suse.de/archive/suse-security-announce/2006-Feb/0010.html
- http://marc.info/?l=linux-kernel&m=112508479120081&w=2
- http://marc.info/?l=linux-kernel&m=112533899509033&w=2
- http://secunia.com/advisories/18203
- http://secunia.com/advisories/18510
- http://secunia.com/advisories/18562
- http://secunia.com/advisories/19038
- http://secunia.com/advisories/19369
- http://secunia.com/advisories/19374
- http://www.debian.org/security/2006/dsa-1017
- http://www.debian.org/security/2006/dsa-1018
- http://www.redhat.com/support/errata/RHSA-2006-0101.html
- http://www.redhat.com/support/errata/RHSA-2006-0140.html
- http://www.securityfocus.com/bid/16043
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.