Red Hat Bugzilla – Bug 1303072
CVE-2003-1604 kernel: Missing NULL pointer check in nf_nat_redirect_ipv4
Last modified: 2016-01-29 08:12:08 EST
When a device doesn't have an IP address, as in ifconfig eth0 0.0.0.0, then dev->ip_ptr->indev == NULL. It is possible to craft a packet that crashes the kernel. Original bug report with fix: http://marc.info/?l=netfilter-devel&m=106668497403047&w=2 CVE assignment: http://seclists.org/oss-sec/2016/q1/226