CVE-2007-1497
Linux kernel <2.6.20.3 - Info Disclosure
Title source: llmDescription
nf_conntrack in netfilter in the Linux kernel before 2.6.20.3 does not set nfctinfo during reassembly of fragmented packets, which leaves the default value as IP_CT_ESTABLISHED and might allow remote attackers to bypass certain rulesets using IPv6 fragments.
References (17)
Scores
EPSS
0.0202
EPSS Percentile
83.5%
Classification
Status
draft
Affected Products (1)
linux/linux_kernel
< 2.6.20.2
Timeline
Published
Mar 16, 2007
Tracked Since
Feb 18, 2026