Bug 278021

Summary: CVE-2007-4567 ipv6_hop_jumbo remote system crash
Product: [Other] Security Response Reporter: Marcel Holtmann <holtmann>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED NOTABUG QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: davem, dhoward, kernel-mgr, tgraf
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2007-09-05 16:07:22 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 548641    

Description Marcel Holtmann 2007-09-05 08:43:15 UTC
From Victor Julien:

There exists a way to crash the Linux kernel by sending a single IPv6 packet at it.

Comment 4 Marcel Holtmann 2007-09-05 08:52:11 UTC
Created attachment 187121 [details]
Linus thinks this patch fixed it upstream (not verified)

Comment 6 Thomas Graf 2007-09-05 15:21:47 UTC
Note, no RHEL tree is affected to this. This bug has been introduced with the
patch [IPV6]: Per-interface statistics support. which was accepted in 2.6.20
therefore the vulnerable code was never included in any of our releases.