The IPv6 fragmentation implementation in the Linux kernel through 4.11.1 does not consider that the nexthdr field may be associated with an invalid option, which allows local users to cause a denial of service (out-of-bounds read and BUG) or possibly have unspecified other impact via crafted socket and send system calls.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2017-05-19 07:29
Updated : 2025-04-20 01:37
NVD link : CVE-2017-9074
Mitre link : CVE-2017-9074
CVE.ORG link : CVE-2017-9074
JSON object : View
Products Affected
linux
- linux_kernel
CWE
CWE-125
Out-of-bounds Read