Posted Feb 9, 2006 9:25 UTC (Thu) by mjcox@redhat.com (subscriber, #31775)
[Link]
This issue was discovered by Dave Jones. As Dave notes it's so far proved difficult to reliably trigger (my attempts so far succeed in logging dst badness messages and messing up future ICMP packet receipts, but haven't triggered a crash).
This vulnerability was introduced into the Linux kernel in version 2.6.12 and therefore does not affect users of Red Hat Enterprise Linux 2.1, 3, or 4. An update for Fedora Core 4 was released yesterday.