CVE-2007-3642
Linux Kernel < 2.6.20.14 - Numeric Error
Title source: ruleDescription
The decode_choice function in net/netfilter/nf_conntrack_h323_asn1.c in the Linux kernel before 2.6.20.15, 2.6.21.x before 2.6.21.6, and before 2.6.22 allows remote attackers to cause a denial of service (crash) via an encoded, out-of-range index value for a choice field, which triggers a NULL pointer dereference.
References (13)
Scores
EPSS
0.0235
EPSS Percentile
84.7%
Classification
CWE
CWE-189
Status
draft
Affected Products (50)
linux/linux_kernel
< 2.6.20.14
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
... and 35 more
Timeline
Published
Jul 10, 2007
Tracked Since
Feb 18, 2026