Linux Kernel IPv6 Out-of-bounds Memory Read Vulnerability
Last Update Date:
9 Feb 2017 11:43
Release Date:
9 Feb 2017
4199
Views
RISK: Medium Risk
TYPE: Operating Systems - Linux

A vulnerability has been identified in the Linux kernel. A remote user can obtain potentially sensitive information or cause denial of service conditions on the target system by sending specially crafted data to trigger an out-of-bounds memory read access in ip6gre_err().
Impact
- Denial of Service
- Information Disclosure
System / Technologies affected
- net/ipv6/ip6_gre.c
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- The vendor has issued a source code fix:
https://git.kernel.org/cgit/linux/kernel/git/davem/net.git/commit/?id=7892032cfe67f4bde6fc2ee967e45a8fbaf33756
Vulnerability Identifier
Source
Related Link
Share with