CVE-2005-3274
published 2005-10-21CVE-2005-3274: Race condition in ip_vs_conn_flush in Linux 2.6 before 2.6.13 and 2.4 before 2.4.32-pre2, when running on SMP systems, allows local users to cause a denial of…
PriorityP412medium4.7CVSS 3.1
AVLACHPRLUINSUCNINAH
EPSS
0.39%
32.2th percentile
Race condition in ip_vs_conn_flush in Linux 2.6 before 2.6.13 and 2.4 before 2.4.32-pre2, when running on SMP systems, allows local users to cause a denial of service (null dereference) by causing a connection timer to expire while the connection table is being flushed before the appropriate lock is acquired.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| linux | linux_kernel | 2.4.0 – 2.4.31 | — |
| linux | linux_kernel | >= 2.6.0 < 2.6.13 | 2.6.13 |
CVSS provenance
nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.01.2LOWAV:L/AC:H/Au:N/C:N/I:N/A:P
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2005-11-22
CVE-2005-3180 Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Linux kernel vulnerabilities
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
security flaw
vendor_redhat·2005-06-28·CVSS 4.7
CVE-2005-3274 [MEDIUM] security flaw
security flaw
Race condition in ip_vs_conn_flush in Linux 2.6 before 2.6.13 and 2.4 before 2.4.32-pre2, when running on SMP systems, allows local users to cause a denial of service (null dereference) by causing a connection timer to expire while the connection table is being flushed before the appropriate lock is acquired.
GHSA
GHSA-53p3-f48x-w9j5: Race condition in ip_vs_conn_flush in Linux 2
ghsa_unreviewed·2022-05-01
CVE-2005-3274 [LOW] CWE-476 GHSA-53p3-f48x-w9j5: Race condition in ip_vs_conn_flush in Linux 2
Race condition in ip_vs_conn_flush in Linux 2.6 before 2.6.13 and 2.4 before 2.4.32-pre2, when running on SMP systems, allows local users to cause a denial of service (null dereference) by causing a connection timer to expire while the connection table is being flushed before the appropriate lock is acquired.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2005-3274 security flaw
bugzilla·2018-08-16·CVSS 4.7
CVE-2005-3274 [MEDIUM] CVE-2005-3274 security flaw
CVE-2005-3274 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Race condition in ip_vs_conn_flush in Linux 2.6 before 2.6.13 and 2.4 before 2.4.32-pre2, when running on SMP systems, allows local users to cause a denial of service (null dereference) by causing a connection timer to expire while the connection table is being flushed before the appropriate lock is acquired.
Bugzilla
CVE-2005-3274 ip_vs_conn_flush race
bugzilla·2005-10-21·CVSS 4.7
CVE-2005-3274 [MEDIUM] CVE-2005-3274 ip_vs_conn_flush race
CVE-2005-3274 ip_vs_conn_flush race
CVE-2005-3274 states:
Race condition in ip_vs_conn_flush in Linux 2.6 before 2.6.13
and 2.4 before 2.4.32-pre2, when running on SMP systems,
allows local users to cause a denial of service (null
dereference) by causing a connection timer to expire while the
connection table is being flushed before the appropriate lock
is acquired.
http://linux.bkbits.net:8080/linux-2.4/cset@42e69d4edEXsgo_fbmvtFPjfALoEug
This issue looks to affect rhel2.1 ipf because of the backport of ipvs in
linux-2.4.18-ipvs-1.0.3.patch
Note for RHEL3 we updated the similar backported patch we included for U6.
RHEL2.1 x86 does not look vulnerable as it uses a more outdated version of the
ipvs code.
Discussion:
An advisory has been issued which should help the problem
described i
Bugzilla
Multiple Kernel vulnerabilities
bugzilla·2005-05-11
[MEDIUM] Multiple Kernel vulnerabilities
Multiple Kernel vulnerabilities
From Bugzilla Helper:
User-Agent: Mozilla/5.0 (Mozilla rulez!)
Description of problem:
Paul Starzetz of iSEC has found yet another bug in binfmt_elf.c. It can be abused to crash the kernel, perhaps even to break into the kernel land. See the advisory for details.
Version-Release number of selected component (if applicable):
How reproducible:
Didn't try
Steps to Reproduce:
Additional info:
I've got a quick and dirty patch. I'll submit it ASAP.
Discussion:
Grr...Bugzilla assigned the bug to [email protected] rather than to
[email protected]
---
Created attachment 114264
The patch for CAN-2005-1263
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
This patch can be applied to FL kernel 2.4.20-43:
402e548b02382c015d6f5e5704370a1ba546598b
li
http://lkml.org/lkml/2005/6/23/249http://lkml.org/lkml/2005/6/24/173http://secunia.com/advisories/17826http://secunia.com/advisories/18056http://secunia.com/advisories/18684http://secunia.com/advisories/18977http://www.debian.org/security/2005/dsa-922http://www.kernel.org/git/?p=linux/kernel/git/marcelo/linux-2.4.git%3Ba=commit%3Bh=e684f066dff5628bb61ad1912de6e8058b5b4c7dhttp://www.mandriva.com/security/advisories?name=MDKSA-2005:218http://www.mandriva.com/security/advisories?name=MDKSA-2005:219http://www.mandriva.com/security/advisories?name=MDKSA-2005:220http://www.mandriva.com/security/advisories?name=MDKSA-2005:235http://www.redhat.com/support/errata/RHSA-2005-663.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0190.htmlhttp://www.securityfocus.com/archive/1/427980/100/0/threadedhttp://www.securityfocus.com/archive/1/427981/100/0/threadedhttp://www.securityfocus.com/bid/15528http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:044https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11723https://usn.ubuntu.com/219-1/http://lkml.org/lkml/2005/6/23/249http://lkml.org/lkml/2005/6/24/173http://secunia.com/advisories/17826http://secunia.com/advisories/18056http://secunia.com/advisories/18684http://secunia.com/advisories/18977http://www.debian.org/security/2005/dsa-922http://www.kernel.org/git/?p=linux/kernel/git/marcelo/linux-2.4.git%3Ba=commit%3Bh=e684f066dff5628bb61ad1912de6e8058b5b4c7dhttp://www.mandriva.com/security/advisories?name=MDKSA-2005:218http://www.mandriva.com/security/advisories?name=MDKSA-2005:219http://www.mandriva.com/security/advisories?name=MDKSA-2005:220http://www.mandriva.com/security/advisories?name=MDKSA-2005:235http://www.redhat.com/support/errata/RHSA-2005-663.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0190.htmlhttp://www.securityfocus.com/archive/1/427980/100/0/threadedhttp://www.securityfocus.com/archive/1/427981/100/0/threadedhttp://www.securityfocus.com/bid/15528http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:044https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11723https://usn.ubuntu.com/219-1/
2005-10-21
Published