CVE-2007-6282Redhat Enterprise Linux vulnerability

CWE-165 documents5 sources
Severity
7.1HIGHNVD
EPSS
2.4%
top 14.78%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 8
Latest updateMay 1

Description

The IPsec implementation in Linux kernel before 2.6.25 allows remote routers to cause a denial of service (crash) via a fragmented ESP packet in which the first fragment does not contain the entire ESP header and IV.

CVSS vector

AV:N/AC:M/C:N/I:N/A:CExploitability: 8.6 | Impact: 6.9

Affected Packages1 packages

Also affects: Enterprise Linux as_4, es_4, ws_4

🔴Vulnerability Details

1
GHSA
GHSA-q9hv-wmpx-m7g2: The IPsec implementation in Linux kernel before 22022-05-01

📋Vendor Advisories

2
Ubuntu
Linux kernel vulnerabilities2008-07-15
Red Hat
IPSec ESP kernel panics2008-02-22

💬Community

1
Bugzilla
CVE-2007-6282 IPSec ESP kernel panics2007-11-29