CVE-2009-1360
Linux Kernel < 2.6.29 - Denial of Service via IPv6 Packet Handling
Title source: llmDescription
The __inet6_check_established function in net/ipv6/inet6_hashtables.c in the Linux kernel before 2.6.29, when Network Namespace Support (aka NET_NS) is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) via vectors involving IPv6 packets.
References (9)
Core 9
Core References
Vendor Advisory vendor-advisory
x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2009:135
Vendor Advisory vendor-advisory
x_refsource_ubuntu
http://www.ubuntu.com/usn/usn-793-1
Exploit x_refsource_misc
http://xorl.wordpress.com/2009/04/21/linux-kernel-net_ns-ipv6-null-pointer-dereference/
Patch, Vendor Advisory x_refsource_confirm
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.29
Mailing List vendor-advisory
x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00002.html
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/35656
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/34602
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/35387
Scores
EPSS
0.0319
EPSS Percentile
86.9%
Details
Status
published
Products (50)
linux/linux_kernel
2.2.27
linux/linux_kernel
2.4.36
linux/linux_kernel
2.4.36.1
linux/linux_kernel
2.4.36.2
linux/linux_kernel
2.4.36.3
linux/linux_kernel
2.4.36.4
linux/linux_kernel
2.4.36.5
linux/linux_kernel
2.4.36.6
linux/linux_kernel
2.6
linux/linux_kernel
2.6.0
... and 40 more
Published
Apr 22, 2009
Tracked Since
Feb 18, 2026