Data_len paremeter of sock_alloc_send_pskb() function is not validated before setting frags of allocated skb, which can lead to heap overflow. On Red Hat Enterprise Linux 5 a user having access to TUN/TAP virtual device could use this flaw to crash the system or to potentially escalate their privileges. The resulting CVSS score is 6.2. On Red Hat Enterprise Linux 6 a privileged guest user could use this flaw to crash the host or to potentially escalate their privileges on the host. The resulting CVSS score is 7.4.
This issue has been addressed in following products: Red Hat Enterprise Linux 5 Via RHSA-2012:0690 https://rhn.redhat.com/errata/RHSA-2012-0690.html
This issue has been addressed in following products: Red Hat Enterprise Linux 6 Via RHSA-2012:0743 https://rhn.redhat.com/errata/RHSA-2012-0743.html
This issue has been addressed in following products: Red Hat Enterprise Linux 5.6 EUS - Server Only Via RHSA-2012:1087 https://rhn.redhat.com/errata/RHSA-2012-1087.html