CVE-2005-3809

Linux Kernel 2.6.14-2.6.14.3 - Denial of Service via Null Dereference in nfattr_to_tcp

Title source: llm
STIX 2.1

Description

The nfattr_to_tcp function in ip_conntrack_proto_tcp.c in ctnetlink in Linux kernel 2.6.14 up to 2.6.14.3 allows attackers to cause a denial of service (kernel oops) via an update message without private protocol information, which triggers a null dereference.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/24114
Mailing List mailing-list x_refsource_mlist
http://marc.info/?l=linux-kernel&m=113269476105016&w=2

Scores

EPSS 0.0205
EPSS Percentile 79.5%

Details

Status published
Products (4)
linux/linux_kernel 2.6.14 (5 CPE variants)
linux/linux_kernel 2.6.14.1
linux/linux_kernel 2.6.14.2
linux/linux_kernel 2.6.14.3
Published Nov 25, 2005
Tracked Since Feb 18, 2026