CVE-2009-0778
The icmp_send function in net/ipv4/icmp.c in the Linux kernel before 2.6.25, when configured as a router with a REJECT route, does not properly manage the Protocol Independent Destination Cache (aka DST) in some situations involving transmission of an…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.62%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The icmp_send function in net/ipv4/icmp.c in the Linux kernel before 2.6.25, when configured as a router with a REJECT route, does not properly manage the Protocol Independent Destination Cache (aka DST) in some situations involving transmission of an ICMP Host Unreachable message, which allows remote attackers to cause a denial of service (connectivity outage) by sending a large series of packets to many destination IP addresses within this REJECT route, related to an "rt_cache leak."
- CVSS 2.0
- 7.1 HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
- EPSS
- 4.62% probability · 91th percentile
- CISA KEV
- Not listed
- Affected
- linux/linux kernel · vmware/vcenter · vmware/virtualcenter · vmware/server · vmware/esx · vmware/vma
- Source
- secalert@redhat.com
References
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=7c0ecc4c4f8fd90988aab8a95297b9c0038b6160
- http://openwall.com/lists/oss-security/2009/03/11/2Mailing List, Third Party Advisory
- http://secunia.com/advisories/33758Broken Link
- http://secunia.com/advisories/37471Broken Link
- http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.25Broken Link
- http://www.redhat.com/support/errata/RHSA-2009-0326.htmlBroken Link
- http://www.securityfocus.com/archive/1/507985/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/34084Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1021958Third Party Advisory, VDB Entry
- http://www.vmware.com/security/advisories/VMSA-2009-0016.htmlThird Party Advisory
- http://www.vupen.com/english/advisories/2009/3316Broken Link
- https://bugzilla.redhat.com/show_bug.cgi?id=485163Exploit, Issue Tracking, Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/49199Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10215Third Party Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7867Third Party Advisory
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=7c0ecc4c4f8fd90988aab8a95297b9c0038b6160
- http://openwall.com/lists/oss-security/2009/03/11/2Mailing List, Third Party Advisory
- http://secunia.com/advisories/33758Broken Link
- http://secunia.com/advisories/37471Broken Link
- http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.25Broken Link
- http://www.redhat.com/support/errata/RHSA-2009-0326.htmlBroken Link
- http://www.securityfocus.com/archive/1/507985/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/34084Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1021958Third Party Advisory, VDB Entry
- http://www.vmware.com/security/advisories/VMSA-2009-0016.htmlThird Party Advisory
- http://www.vupen.com/english/advisories/2009/3316Broken Link
- https://bugzilla.redhat.com/show_bug.cgi?id=485163Exploit, Issue Tracking, Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/49199Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10215Third Party Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7867Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.