Hide Forgot
Integer overflow vulnerability in ip6_find_1stfragopt() function was found. Local attacker that has privileges to open raw socket can cause infinite loop inside ip6_find_1stfragopt() function. Upstream patch: https://git.kernel.org/pub/scm/linux/kernel/git/davem/net.git/commit/?id=6399f1fae4ec29fab5ec76070435555e256ca3a6 What is a denial of service: https://access.redhat.com/denial-of-service-flaw-type
Created kernel tracking bugs for this issue: Affects: fedora-all [bug 1473650]
Statement: This issue affects the Linux kernel packages as shipped with Red Hat Enterprise Linux 6, 7 and MRG-2. Future Linux kernel updates for the respective releases may address this issue. This issue affects the Linux kernel packages as shipped with Red Hat Enterprise Linux 5 and does not qualify for inclusion as part of the Red Hat Enterprise Linux 5 lifecycle. For more information on the lifecycle see https://access.redhat.com/support/policy/updates/errata
This issue has been addressed in the following products: Red Hat Enterprise MRG 2 Via RHSA-2017:2918 https://access.redhat.com/errata/RHSA-2017:2918
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2017:2930 https://access.redhat.com/errata/RHSA-2017:2930
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2017:2931 https://access.redhat.com/errata/RHSA-2017:2931
This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Via RHSA-2018:0169 https://access.redhat.com/errata/RHSA-2018:0169