David Ahern

2 exploits Active since Dec 2016
CVE-2016-9919 WRITEUP HIGH WRITEUP
Linux Kernel < 4.9 - Improper Input Validation
The icmp6_send function in net/ipv6/icmp.c in the Linux kernel through 4.8.12 omits a certain check of the dst data structure, which allows remote attackers to cause a denial of service (panic) via a fragmented IPv6 packet.
CVSS 7.5
CVE-2023-3022 WRITEUP MEDIUM WRITEUP
Linux Kernel - Use After Free
A flaw was found in the IPv6 module of the Linux kernel. The arg.result was not used consistently in fib6_rule_lookup, sometimes holding rt6_info and other times fib6_info. This was not accounted for in other parts of the code where rt6_info was expected unconditionally, potentially leading to a kernel panic in fib6_rule_suppress.
CVSS 5.5