CVE-2008-2750
The pppol2tp_recvmsg function in drivers/net/pppol2tp.c in the Linux kernel 2.6 before 2.6.26-rc6 allows remote attackers to cause a denial of service (kernel heap memory corruption and system crash) and possibly have unspecified other impact via a…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.82%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The pppol2tp_recvmsg function in drivers/net/pppol2tp.c in the Linux kernel 2.6 before 2.6.26-rc6 allows remote attackers to cause a denial of service (kernel heap memory corruption and system crash) and possibly have unspecified other impact via a crafted PPPOL2TP packet that results in a large value for a certain length variable.
- CVSS 2.0
- 7.8 HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
- EPSS
- 3.82% probability · 89th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- linux/linux kernel
- Source
- cve@mitre.org
References
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=6b6707a50c7598a83820077393f8823ab791abf8
- http://kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.26-rc6
- http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00009.html
- http://secunia.com/advisories/30719Vendor Advisory
- http://secunia.com/advisories/30901
- http://secunia.com/advisories/30920
- http://secunia.com/advisories/31107
- http://secunia.com/advisories/31202
- http://securitytracker.com/id?1020297
- http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0207
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:167
- http://www.openwall.com/lists/oss-security/2008/06/19/3
- http://www.securityfocus.com/bid/29747Patch
- http://www.ubuntu.com/usn/usn-625-1
- http://www.vupen.com/english/advisories/2008/1854
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43111
- https://issues.rpath.com/browse/RPL-2629
- https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00082.html
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=6b6707a50c7598a83820077393f8823ab791abf8
- http://kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.26-rc6
- http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00009.html
- http://secunia.com/advisories/30719Vendor Advisory
- http://secunia.com/advisories/30901
- http://secunia.com/advisories/30920
- http://secunia.com/advisories/31107
- http://secunia.com/advisories/31202
- http://securitytracker.com/id?1020297
- http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0207
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:167
- http://www.openwall.com/lists/oss-security/2008/06/19/3
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.