CVE-2007-5501

Linux Kernel 2.6.21-2.6.23.7 and 2.6.24-rc-2.6.24-rc2 - Denial of Service via Crafted ACK Responses

Title source: llm
STIX 2.1

Description

The tcp_sacktag_write_queue function in net/ipv4/tcp_input.c in Linux kernel 2.6.21 through 2.6.23.7, and 2.6.24-rc through 2.6.24-rc2, allows remote attackers to cause a denial of service (crash) via crafted ACK responses that trigger a NULL pointer dereference.

References (24)

Core 24
Core References
Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/26474
Various Sources mailing-list x_refsource_mlist
http://lwn.net/Articles/258947/
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/27922
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/27703
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/27919
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/28706
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/38548
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/27664
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2008:044
Vendor Advisory vendor-advisory x_refsource_suse
http://www.novell.com/linux/security/advisories/2007_63_kernel.html
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/29245
Issue Tracking x_refsource_confirm
https://issues.rpath.com/browse/RPL-1965
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/usn-558-1
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/3902
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/usn-574-1
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/28170
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/27888

Scores

EPSS 0.0382
EPSS Percentile 89.1%

Details

CWE
CWE-399
Status published
Products (32)
linux/linux_kernel 2.6.21 (8 CPE variants)
linux/linux_kernel 2.6.21.1
linux/linux_kernel 2.6.21.2
linux/linux_kernel 2.6.21.3
linux/linux_kernel 2.6.21.4
linux/linux_kernel 2.6.21.5
linux/linux_kernel 2.6.21.6
linux/linux_kernel 2.6.21.7
linux/linux_kernel 2.6.22 (8 CPE variants)
linux/linux_kernel 2.6.22.1
... and 22 more
Published Nov 15, 2007
Tracked Since Feb 18, 2026