CVE-2007-2172
published 2007-04-22CVE-2007-2172: A typo in Linux kernel 2.6 before 2.6.21-rc6 and 2.4 before 2.4.35 causes RTA_MAX to be used as an array size instead of RTN_MAX, which leads to an "out of…
PriorityP412medium4.7CVSS 2.0
AVLACMAuNCNINAC
EPSS
0.43%
35.5th percentile
A typo in Linux kernel 2.6 before 2.6.21-rc6 and 2.4 before 2.4.35 causes RTA_MAX to be used as an array size instead of RTN_MAX, which leads to an "out of bound access" by the (1) dn_fib_props (dn_fib.c, DECNet) and (2) fib_props (fib_semantics.c, IPv4) functions.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 2.4.0 < 2.4.35 | 2.4.35 |
| linux | linux_kernel | 2.6.0 – 2.6.20 | — |
CVSS provenance
nvdv2.04.7MEDIUMAV:L/AC:M/Au:N/C:N/I:N/A:C
vendor_ubuntu7.8HIGH
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gxp8-xh27-r994: A typo in Linux kernel 2
ghsa_unreviewed·2022-05-01
CVE-2007-2172 [MEDIUM] CWE-20 GHSA-gxp8-xh27-r994: A typo in Linux kernel 2
A typo in Linux kernel 2.6 before 2.6.21-rc6 and 2.4 before 2.4.35 causes RTA_MAX to be used as an array size instead of RTN_MAX, which leads to an "out of bound access" by the (1) dn_fib_props (dn_fib.c, DECNet) and (2) fib_props (fib_semantics.c, IPv4) functions.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2007-05-24·CVSS 7.8
CVE-2007-1357 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Linux kernel vulnerabilities
Philipp Richter discovered that the AppleTalk protocol handler did
not sufficiently verify the length of packets. By sending a crafted
AppleTalk packet, a remote attacker could exploit this to crash the
kernel. (CVE-2007-1357)
Gabriel Campana discovered that the do_ipv6_setsockopt() function did
not sufficiently verifiy option values for IPV6_RTHDR. A local
attacker could exploit this to trigger a kernel crash. (CVE-2007-1388)
A Denial of Service vulnerability was discovered in the
nfnetlink_log() netfilter function. A remote attacker could exploit
this to trigger a kernel crash. (CVE-2007-1496)
The connection tracking module for IPv6 did not properly handle the
status field when reassembling fragmented packets,
Red Hat
fib_semantics.c out of bounds access vulnerability
vendor_redhat·2007-03-26·CVSS 4.7
CVE-2007-2172 [MEDIUM] fib_semantics.c out of bounds access vulnerability
fib_semantics.c out of bounds access vulnerability
A typo in Linux kernel 2.6 before 2.6.21-rc6 and 2.4 before 2.4.35 causes RTA_MAX to be used as an array size instead of RTN_MAX, which leads to an "out of bound access" by the (1) dn_fib_props (dn_fib.c, DECNet) and (2) fib_props (fib_semantics.c, IPv4) functions.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2007-2172 fib_semantics.c out of bounds access vulnerability
bugzilla·2007-08-01·CVSS 4.7
CVE-2007-2172 [MEDIUM] CVE-2007-2172 fib_semantics.c out of bounds access vulnerability
CVE-2007-2172 fib_semantics.c out of bounds access vulnerability
The Linux kernel is prone to an out-of-bounds-access vulnerability. This issue
occurs because the semantics for IPv4 Forwarding Information Base fail to
adequately bounds-check user-supplied data before accessing an array.
An attacker can exploit this issue to cause denial-of-service conditions.
Arbitrary code execution may also be possible, but this has not been confirmed.
Discussion:
A patch for this issue has been included in build 2.4.21-53.EL.
Bugzilla
CVE-2007-2172 fib_semantics.c out of bounds access vulnerability
bugzilla·2007-08-01·CVSS 4.7
CVE-2007-2172 [MEDIUM] CVE-2007-2172 fib_semantics.c out of bounds access vulnerability
CVE-2007-2172 fib_semantics.c out of bounds access vulnerability
The Linux kernel is prone to an out-of-bounds-access vulnerability. This issue
occurs because the semantics for IPv4 Forwarding Information Base fail to
adequately bounds-check user-supplied data before accessing an array.
An attacker can exploit this issue to cause denial-of-service conditions.
Arbitrary code execution may also be possible, but this has not been confirmed.
Discussion:
*** This bug has been marked as a duplicate of 384471 ***
Bugzilla
CVE-2007-2172 fib_semantics.c out of bounds access vulnerability
bugzilla·2007-08-01·CVSS 4.7
CVE-2007-2172 [MEDIUM] CVE-2007-2172 fib_semantics.c out of bounds access vulnerability
CVE-2007-2172 fib_semantics.c out of bounds access vulnerability
The Linux kernel is prone to an out-of-bounds-access vulnerability. This issue
occurs because the semantics for IPv4 Forwarding Information Base fail to
adequately bounds-check user-supplied data before accessing an array.
An attacker can exploit this issue to cause denial-of-service conditions.
Arbitrary code execution may also be possible, but this has not been confirmed.
Discussion:
*** This bug has been marked as a duplicate of 384481 ***
Bugzilla
CVE-2007-2172 fib_semantics.c out of bounds access vulnerability
bugzilla·2007-06-08·CVSS 4.7
CVE-2007-2172 [MEDIUM] CVE-2007-2172 fib_semantics.c out of bounds access vulnerability
CVE-2007-2172 fib_semantics.c out of bounds access vulnerability
The Linux kernel is prone to an out-of-bounds-access vulnerability. This issue
occurs because the semantics for IPv4 Forwarding Information Base fail to
adequately bounds-check user-supplied data before accessing an array.
An attacker can exploit this issue to cause denial-of-service conditions.
Arbitrary code execution may also be possible, but this has not been confirmed.
Discussion:
committed in stream rhel‑4.5.z build 55.0.1
---
Jason,
Is there a reproducer for this one?
---
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
please fol
Bugzilla
CVE-2007-2172 fib_semantics.c out of bounds access vulnerability
bugzilla·2007-05-04·CVSS 4.7
CVE-2007-2172 [MEDIUM] CVE-2007-2172 fib_semantics.c out of bounds access vulnerability
CVE-2007-2172 fib_semantics.c out of bounds access vulnerability
The Linux kernel is prone to an out-of-bounds-access vulnerability. This issue
occurs because the semantics for IPv4 Forwarding Information Base fail to
adequately bounds-check user-supplied data before accessing an array.
An attacker can exploit this issue to cause denial-of-service conditions.
Arbitrary code execution may also be possible, but this has not been confirmed.
Discussion:
A patch for this issue has been included in build 2.6.18-8.1.4.el5.
---
Confirmed that the patch is in 2.6.18-8.1.4.el5. I take it there is no known
exploit or other test case for this.
---
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of E
http://kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.21-rc6http://rhn.redhat.com/errata/RHSA-2007-0488.htmlhttp://secunia.com/advisories/25068http://secunia.com/advisories/25288http://secunia.com/advisories/25392http://secunia.com/advisories/25838http://secunia.com/advisories/26289http://secunia.com/advisories/26450http://secunia.com/advisories/26620http://secunia.com/advisories/26647http://secunia.com/advisories/27913http://secunia.com/advisories/29058http://secunia.com/advisories/33280http://support.avaya.com/elmodocs2/security/ASA-2007-287.htmhttp://www.debian.org/security/2007/dsa-1356http://www.debian.org/security/2007/dsa-1363http://www.debian.org/security/2008/dsa-1503http://www.debian.org/security/2008/dsa-1504http://www.kernel.org/pub/linux/kernel/v2.4/ChangeLog-2.4.35http://www.mail-archive.com/git-commits-head%40vger.kernel.org/msg08269.htmlhttp://www.mail-archive.com/git-commits-head%40vger.kernel.org/msg08270.htmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2007:171http://www.mandriva.com/security/advisories?name=MDKSA-2007:196http://www.mandriva.com/security/advisories?name=MDKSA-2007:216http://www.redhat.com/support/errata/RHSA-2007-0347.htmlhttp://www.redhat.com/support/errata/RHSA-2007-1049.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0787.htmlhttp://www.securityfocus.com/bid/23447http://www.ubuntu.com/usn/usn-464-1http://www.vupen.com/english/advisories/2007/2690https://exchange.xforce.ibmcloud.com/vulnerabilities/33979https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10764http://kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.21-rc6http://rhn.redhat.com/errata/RHSA-2007-0488.htmlhttp://secunia.com/advisories/25068http://secunia.com/advisories/25288http://secunia.com/advisories/25392http://secunia.com/advisories/25838http://secunia.com/advisories/26289http://secunia.com/advisories/26450http://secunia.com/advisories/26620http://secunia.com/advisories/26647http://secunia.com/advisories/27913http://secunia.com/advisories/29058http://secunia.com/advisories/33280http://support.avaya.com/elmodocs2/security/ASA-2007-287.htmhttp://www.debian.org/security/2007/dsa-1356http://www.debian.org/security/2007/dsa-1363http://www.debian.org/security/2008/dsa-1503http://www.debian.org/security/2008/dsa-1504http://www.kernel.org/pub/linux/kernel/v2.4/ChangeLog-2.4.35http://www.mail-archive.com/git-commits-head%40vger.kernel.org/msg08269.htmlhttp://www.mail-archive.com/git-commits-head%40vger.kernel.org/msg08270.htmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2007:171http://www.mandriva.com/security/advisories?name=MDKSA-2007:196http://www.mandriva.com/security/advisories?name=MDKSA-2007:216http://www.redhat.com/support/errata/RHSA-2007-0347.htmlhttp://www.redhat.com/support/errata/RHSA-2007-1049.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0787.htmlhttp://www.securityfocus.com/bid/23447http://www.ubuntu.com/usn/usn-464-1http://www.vupen.com/english/advisories/2007/2690https://exchange.xforce.ibmcloud.com/vulnerabilities/33979https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10764
2007-04-22
Published