LWN.net Logo

kernel: null pointer dereference

Package(s):kernel CVE #(s):CVE-2009-1298
Created:December 7, 2009 Updated:January 7, 2010
Description:

From the Red Hat bugzilla entry:

Between 2.6.28.10 and 2.6.29, net/ipv4/ip_fragment.c was patched, changing from dev_net(dev) to container_of(...). Unfortunately the goto section (out_fail) on oversized packets inside ip_frag_reasm() didn't get touched up as well. Oversized IP packets cause a NULL pointer dereference and immediate hang.

Alerts:
SuSE SUSE-SA:2010:001 2010-01-07
rPath rPSA-2009-0161-1 2009-12-16
Ubuntu USN-869-1 2009-12-10
Mandriva MDVSA-2009:329 2009-12-09
Slackware SSA:2009-342-01 2009-12-09
Fedora FEDORA-2009-12825 2009-12-07
Fedora FEDORA-2009-12786 2009-12-07

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds