CVE-2002-2438
published 2021-05-18CVE-2002-2438: TCP firewalls could be circumvented by sending a SYN Packets with other flags (like e.g. RST flag) set, which was not correctly discarded by the Linux TCP…
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
3.74%
88.6th percentile
TCP firewalls could be circumvented by sending a SYN Packets with other flags (like e.g. RST flag) set, which was not correctly discarded by the Linux TCP stack after firewalling.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux_kernel | < 2.4.20 | 2.4.20 |
| linux | linux_kernel | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w6mc-fc3q-jpx7: TCP firewalls could be circumvented by sending a SYN Packets with other flags (like e
ghsa_unreviewed·2022-04-21
CVE-2002-2438 [HIGH] CWE-287 GHSA-w6mc-fc3q-jpx7: TCP firewalls could be circumvented by sending a SYN Packets with other flags (like e
TCP firewalls could be circumvented by sending a SYN Packets with other flags (like e.g. RST flag) set, which was not correctly discarded by the Linux TCP stack after firewalling.
Red Hat
CVE-2002-2438: TCP firewalls could be circumvented by sending a SYN Packets with other flags (like e
vendor_redhat·CVSS 7.5
CVE-2002-2438 [HIGH] CVE-2002-2438: TCP firewalls could be circumvented by sending a SYN Packets with other flags (like e
TCP firewalls could be circumvented by sending a SYN Packets with other flags (like e.g. RST flag) set, which was not correctly discarded by the Linux TCP stack after firewalling.
Statement: Not vulnerable. This issue did not affect the Linux kernels as shipped with Red
Hat Enterprise Linux 4, 5, 6, and Red Hat Enterprise MRG.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-2663 iptables: --syn flag bypass
bugzilla·2012-05-30·CVSS 7.5
CVE-2012-2663 [HIGH] CVE-2012-2663 iptables: --syn flag bypass
CVE-2012-2663 iptables: --syn flag bypass
Originally reported as a DoS related issue:
http://git.kernel.org/?p=linux/kernel/git/davem/net-next.git;a=commitdiff;h=fdf5af0daf8019cec2396cdef8fb042d80fe71fa
Denys Fedoryshchenko reported that SYN+FIN attacks were bringing his
linux machines to their limits.
Dont call conn_request() if the TCP flags includes SYN flag
---
This issue also allows bypass of --syn rules in iptables:
http://www.spinics.net/lists/netfilter-devel/msg21248.html
Unfortunately, with current stable Linux kernel release (as well as
with most of the previous versions) blocking TCP packets with the SYN
bit set and the ACK,RST and FIN bits cleared won't prevent incoming
TCP connections.
It should be noted that the combination of SYN+FIN in a TCP-IP packet is generally
Bugzilla
CVE kernel non-issue statements
bugzilla·2010-05-13·CVSS 5.0
[MEDIUM] CVE kernel non-issue statements
CVE kernel non-issue statements
This bug is to collect statements for Linux kernel-related CVE's that do not have their own top-level CVE SRT bug because it did not affect any of our supported kernels. These statements were also referred to as NVD statements and are noted on the NVD web site.
(From bug 589808) Do not change the bug alias, it needs to have "CVE" in the title. You can add extra statements in new comments or editing existing comments and they will be picked up correctly.
Discussion:
Statement CVE-2010-0747:
Not vulnerable. This issue did not affect the versions of the Linux kernel as shipped with Red Hat Enterprise Linux 3, 4, 5 and Red Hat Enterprise MRG as they did not backport an out-of-tree drbd module (drbd8).
Statement CVE-2010-1446:
Not vulnerable. This issue di
http://www.openwall.com/lists/oss-security/2012/02/03/7http://www.openwall.com/lists/oss-security/2012/05/29/8http://www.openwall.com/lists/oss-security/2012/05/30/11http://www.openwall.com/lists/oss-security/2012/05/30/12http://www.openwall.com/lists/oss-security/2012/05/30/13http://www.openwall.com/lists/oss-security/2012/05/30/2http://www.openwall.com/lists/oss-security/2012/05/30/4http://www.openwall.com/lists/oss-security/2012/05/30/8http://www.openwall.com/lists/oss-security/2012/05/30/9http://www.openwall.com/lists/oss-security/2012/05/31/3http://www.openwall.com/lists/oss-security/2014/02/12/8https://bugzilla.suse.com/show_bug.cgi?id=744994%2Chttps://security.netapp.com/advisory/ntap-20210727-0003/https://www.kb.cert.org/vuls/id/464113https://www.kb.cert.org/vuls/id/464113%2Chttps://www.openwall.com/lists/oss-security/2012/02/03/7http://www.openwall.com/lists/oss-security/2012/02/03/7http://www.openwall.com/lists/oss-security/2012/05/29/8http://www.openwall.com/lists/oss-security/2012/05/30/11http://www.openwall.com/lists/oss-security/2012/05/30/12http://www.openwall.com/lists/oss-security/2012/05/30/13http://www.openwall.com/lists/oss-security/2012/05/30/2http://www.openwall.com/lists/oss-security/2012/05/30/4http://www.openwall.com/lists/oss-security/2012/05/30/8http://www.openwall.com/lists/oss-security/2012/05/30/9http://www.openwall.com/lists/oss-security/2012/05/31/3http://www.openwall.com/lists/oss-security/2014/02/12/8https://bugzilla.suse.com/show_bug.cgi?id=744994%2Chttps://security.netapp.com/advisory/ntap-20210727-0003/https://www.kb.cert.org/vuls/id/464113https://www.kb.cert.org/vuls/id/464113%2Chttps://www.openwall.com/lists/oss-security/2012/02/03/7
2021-05-18
Published