CVE-2003-0653

NetBSD <= 1.6.1 - Denial of Service via OSI Networking Kernel Error Response

Title source: llm
STIX 2.1

Description

The OSI networking kernel (sys/netiso) in NetBSD 1.6.1 and earlier does not use a BSD-required "PKTHDR" mbuf when sending certain error responses to the sender of an OSI packet, which allows remote attackers to cause a denial of service (kernel panic or crash) via certain OSI packets.

References (1)

Core 1
Core References
Vendor Advisory vendor-advisory x_refsource_netbsd
ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-010.txt.asc

Scores

EPSS 0.0066
EPSS Percentile 71.2%

Details

Status published
Products (6)
netbsd/netbsd 1.5
netbsd/netbsd 1.5.1
netbsd/netbsd 1.5.2
netbsd/netbsd 1.5.3
netbsd/netbsd 1.6
netbsd/netbsd 1.6.1
Published Aug 27, 2003
Tracked Since Feb 18, 2026