---
title: "CVE-2012-2744\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2012-2744?format=md
keywords: index, follow
---

# CVE-2012-2744

Publication date 10 July 2012

Last updated 4 July 2026

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

net/ipv6/netfilter/nf\_conntrack\_reasm.c in the Linux kernel before 2.6.34,
when the nf\_conntrack\_ipv6 module is enabled, allows remote attackers to
cause a denial of service (NULL pointer dereference and system crash) via
certain types of fragmented IPv6 packets.

### From the Ubuntu Security Team

An error was found in the Linux kernel's IPv6 netfilter when connection
tracking is enabled. A remote attacker could exploit this flaw to crash a
system if it is using IPv6 with the nf\_contrack\_ipv6 kernel module loaded.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2012-2744?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| linux | 12.04 LTS precise | Not affected |
| 11.10 oneiric | Not affected |
| 11.04 natty | Not affected |
| 10.04 LTS lucid | Not affected |
| 8.04 LTS hardy | Fixed 2.6.24-32.104 |
| linux-armadaxp | 12.04 LTS precise | Not affected |
| 11.10 oneiric | Not in release |
| 11.04 natty | Not in release |
| 10.04 LTS lucid | Not in release |
| 8.04 LTS hardy | Not in release |
| linux-ec2 | 12.04 LTS precise | Not in release |
| 11.10 oneiric | Not in release |
| 11.04 natty | Not in release |
| 10.04 LTS lucid | Not affected |
| 8.04 LTS hardy | Not in release |
| linux-fsl-imx51 | 12.04 LTS precise | Not in release |
| 11.10 oneiric | Not in release |
| 11.04 natty | Not in release |
| 10.04 LTS lucid | Ignored end of life |
| 8.04 LTS hardy | Not in release |
| linux-linaro-omap | 12.04 LTS precise | Ignored end of life |
| 11.10 oneiric | Ignored end of life |
| 11.04 natty | Ignored end of life |
| 10.04 LTS lucid | Not in release |
| 8.04 LTS hardy | Not in release |
| linux-linaro-shared | 12.04 LTS precise | Ignored end of life |
| 11.10 oneiric | Ignored end of life |
| 11.04 natty | Not in release |
| 10.04 LTS lucid | Not in release |
| 8.04 LTS hardy | Not in release |
| linux-linaro-vexpress | 12.04 LTS precise | Ignored end of life |
| 11.10 oneiric | Ignored end of life |
| 11.04 natty | Ignored end of life |
| 10.04 LTS lucid | Not in release |
| 8.04 LTS hardy | Not in release |
| linux-lts-backport-maverick | 12.04 LTS precise | Not in release |
| 11.10 oneiric | Not in release |
| 11.04 natty | Not in release |
| 10.04 LTS lucid | Ignored end of life |
| 8.04 LTS hardy | Not in release |
| linux-lts-backport-natty | 12.04 LTS precise | Not in release |
| 11.10 oneiric | Not in release |
| 11.04 natty | Not in release |
| 10.04 LTS lucid | Not affected |
| 8.04 LTS hardy | Not in release |
| linux-lts-backport-oneiric | 12.04 LTS precise | Not in release |
| 11.10 oneiric | Not in release |
| 11.04 natty | Not in release |
| 10.04 LTS lucid | Not affected |
| 8.04 LTS hardy | Not in release |
| linux-mvl-dove | 12.04 LTS precise | Not in release |
| 11.10 oneiric | Not in release |
| 11.04 natty | Not in release |
| 10.04 LTS lucid | Ignored end of life |
| 8.04 LTS hardy | Not in release |
| linux-qcm-msm | 12.04 LTS precise | Ignored end of life |
| 11.10 oneiric | Ignored end of life |
| 11.04 natty | Ignored end of life |
| 10.04 LTS lucid | Ignored end of life |
| 8.04 LTS hardy | Not in release |
| linux-ti-omap4 | 12.04 LTS precise | Not affected |
| 11.10 oneiric | Not affected |
| 11.04 natty | Not affected |
| 10.04 LTS lucid | Not in release |
| 8.04 LTS hardy | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2012-2744?format=md#patch-details)

## Notes

---

### [jdstrand](https://launchpad.net/~jdstrand)

linux-armadaxp is maintained by OEM
commit is from 2010. Ubuntu 10.04 LTS confirmed as not affected
downgrading to 'medium' (and therefore will follow the standard
kernel cadence update process). This is a 2 year old fix that only affects
Ubuntu 8.04 LTS when using IPv6.

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| linux | * Vendor:   <https://rhn.redhat.com/errata/RHSA-2012-1064.html> * Introduced by   [1da177e](https://git.kernel.org/linus/1da177e4c3f41524e886b7f1b8a0c1fc7321cac2),   fixed by   [9e2dcf7](https://git.kernel.org/linus/9e2dcf72023d1447f09c47d77c99b0c49659e5ce) |

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2744)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2012-2744)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2012-2744)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2012-2744)

### Related Ubuntu Security Notices (USN)

+ [USN-1507-1](https://usn.ubuntu.com/USN-1507-1)
+ Linux kernel vulnerabilities
+ 17 July 2012

### Other references

* <https://rhn.redhat.com/errata/RHSA-2012-1064.html>
* <https://www.cve.org/CVERecord?id=CVE-2012-2744>
