CVE-2007-4567

Publication date 21 December 2007

Last updated 24 July 2024


Ubuntu priority

The ipv6_hop_jumbo function in net/ipv6/exthdrs.c in the Linux kernel before 2.6.22 does not properly validate the hop-by-hop IPv6 extended header, which allows remote attackers to cause a denial of service (NULL pointer dereference and kernel panic) via a crafted IPv6 packet.

Read the notes from the security team

Status

Package Ubuntu Release Status
linux-source-2.6.15 6.06 LTS dapper
Not affected
linux-source-2.6.17 6.10 edgy
Not affected
linux-source-2.6.20 7.04 feisty
Fixed 2.6.20-16.33
linux-source-2.6.22 7.10 gutsy
Not affected

Notes


kees

introduced in 2.6.20, fixed in 2.6.22

References

Related Ubuntu Security Notices (USN)

    • USN-574-1
    • Linux kernel vulnerabilities
    • 4 February 2008
    • USN-558-1
    • Linux kernel vulnerabilities
    • 19 December 2007

Other references