CVE-2014-7207

Linux Kernel 3.2.x-3.2.63 - Denial of Service via IPv6 Select Ident Function

Title source: llm
STIX 2.1

Description

A certain Debian patch to the IPv6 implementation in the Linux kernel 3.2.x through 3.2.63 does not properly validate arguments in ipv6_select_ident function calls, which allows local users to cause a denial of service (NULL pointer dereference and system crash) by leveraging (1) tun or (2) macvtap device access.

References (6)

Core 6
Core References
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2418-1
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2417-1
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2014/dsa-3060
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2014/11/02/1
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/70867

Scores

EPSS 0.0038
EPSS Percentile 30.4%

Details

Status published
Products (42)
linux/linux_kernel 3.2 (8 CPE variants)
linux/linux_kernel 3.2.1 (2 CPE variants)
linux/linux_kernel 3.2.2
linux/linux_kernel 3.2.3
linux/linux_kernel 3.2.4
linux/linux_kernel 3.2.5
linux/linux_kernel 3.2.6
linux/linux_kernel 3.2.7
linux/linux_kernel 3.2.8
linux/linux_kernel 3.2.9
... and 32 more
Published Nov 10, 2014
Tracked Since Feb 18, 2026