The nfnetlink_log in the netfilter code allows attackers to cause a denial of
service (crash) via unspecified vectors involving the (1) nfulnl_recv_config
function, (2) using "multiple packets per netlink message", and (3) bridged
packets, which trigger a NULL pointer dereference.
A patch for this issue has been included in build 2.6.18-8.1.4.el5.
confirmed fix is in 2.6.18-8.1.4.el5.
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.