CVE-2005-2456
MEDIUMLinux Kernel - Improper Locking
Title source: ruleDescription
Array index overflow in the xfrm_sk_policy_insert function in xfrm_user.c in Linux kernel 2.6 allows local users to cause a denial of service (oops or deadlock) and possibly execute arbitrary code via a p->dir value that is larger than XFRM_POLICY_OUT, which is used as an index in the sock->sk_policy array.
References (23)
... and 3 more
Scores
CVSS v3
5.5
EPSS
0.0012
EPSS Percentile
30.2%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Classification
CWE
CWE-667
Status
draft
Affected Products (2)
linux/linux_kernel
debian/debian_linux
Timeline
Published
Aug 04, 2005
Tracked Since
Feb 18, 2026