CVE-2008-3276
Publication date 18 August 2008
Last updated 24 July 2024
Ubuntu priority
Integer overflow in the dccp_setsockopt_change function in net/dccp/proto.c in the Datagram Congestion Control Protocol (DCCP) subsystem in the Linux kernel 2.6.17-rc1 through 2.6.26.2 allows remote attackers to cause a denial of service (panic) via a crafted integer value, related to Change L and Change R options without at least one byte in the dccpsf_val field.
From the Ubuntu Security Team
It was discovered that the Datagram Congestion Control Protocol (DCCP) did not correctly validate its arguments. If DCCP was in use, a remote attacker could send specially crafted network traffic and cause a system crash, leading to a denial of service.
Status
Package | Ubuntu Release | Status |
---|---|---|
linux | 8.04 LTS hardy |
Fixed 2.6.24-21.43
|
7.10 gutsy | Not in release | |
7.04 feisty | Not in release | |
6.06 LTS dapper | Not in release | |
linux-source-2.6.15 | 8.04 LTS hardy | Not in release |
7.10 gutsy | Not in release | |
7.04 feisty | Not in release | |
6.06 LTS dapper |
Not affected
|
|
linux-source-2.6.20 | 8.04 LTS hardy | Not in release |
7.10 gutsy | Not in release | |
7.04 feisty | Ignored end of life | |
6.06 LTS dapper | Not in release | |
linux-source-2.6.22 | 8.04 LTS hardy | Not in release |
7.10 gutsy |
Fixed 2.6.22-15.59
|
|
7.04 feisty | Not in release | |
6.06 LTS dapper | Not in release |