CVE-2002-2254
Linux Kernel 2.4-2.4.19 and 2.5-2.5.31 - Unauthorized Network Traffic Access via Netfilter IP Packet Queuing
Title source: llmDescription
The experimental IP packet queuing feature in Netfilter / IPTables in Linux kernel 2.4 up to 2.4.19 and 2.5 up to 2.5.31, when a privileged process exits and network traffic is not being queued, may allow a later process with the same Process ID (PID) to access certain network traffic that would otherwise be restricted.
References (3)
Core 3
Core References
Third Party Advisory mailing-list
x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2002-12/0025.html
Patch vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/6305
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/10756
Scores
EPSS
0.0036
EPSS Percentile
29.2%
Details
CWE
CWE-264
Status
published
Products (22)
linux/linux_kernel
2.4.0 (13 CPE variants)
linux/linux_kernel
2.4.1
linux/linux_kernel
2.4.10
linux/linux_kernel
2.4.11 (2 CPE variants)
linux/linux_kernel
2.4.12
linux/linux_kernel
2.4.13
linux/linux_kernel
2.4.14
linux/linux_kernel
2.4.15
linux/linux_kernel
2.4.16
linux/linux_kernel
2.4.17
... and 12 more
Published
Dec 31, 2002
Tracked Since
Feb 18, 2026