CVE-2011-1927

Linux Kernel < 2.6.39 - Denial of Service via ICMP_TIME_EXCEEDED Packet Handling

Title source: llm
STIX 2.1

Description

The ip_expire function in net/ipv4/ip_fragment.c in the Linux kernel before 2.6.39 does not properly construct ICMP_TIME_EXCEEDED packets after a timeout, which allows remote attackers to cause a denial of service (invalid pointer dereference) via crafted fragmented packets.

Scores

EPSS 0.0259
EPSS Percentile 83.8%

Details

Status published
Products (9)
linux/linux_kernel 2.6.38 (9 CPE variants)
linux/linux_kernel 2.6.38.1
linux/linux_kernel 2.6.38.2
linux/linux_kernel 2.6.38.3
linux/linux_kernel 2.6.38.4
linux/linux_kernel 2.6.38.5
linux/linux_kernel 2.6.38.6
linux/linux_kernel 2.6.38.7
linux/linux_kernel < 2.6.38.8
Published Jun 13, 2012
Tracked Since Feb 18, 2026