CVE-2007-6282
published 2008-05-08CVE-2007-6282: The IPsec implementation in Linux kernel before 2.6.25 allows remote routers to cause a denial of service (crash) via a fragmented ESP packet in which the…
PriorityP425high7.1CVSS 2.0
AVNACMAuNCNINAC
EPSS
2.45%
82.8th percentile
The IPsec implementation in Linux kernel before 2.6.25 allows remote routers to cause a denial of service (crash) via a fragmented ESP packet in which the first fragment does not contain the entire ESP header and IV.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_desktop | — | — |
CVSS provenance
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
vendor_redhat7.1HIGH
vendor_ubuntu7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q9hv-wmpx-m7g2: The IPsec implementation in Linux kernel before 2
ghsa_unreviewed·2022-05-01
CVE-2007-6282 [HIGH] GHSA-q9hv-wmpx-m7g2: The IPsec implementation in Linux kernel before 2
The IPsec implementation in Linux kernel before 2.6.25 allows remote routers to cause a denial of service (crash) via a fragmented ESP packet in which the first fragment does not contain the entire ESP header and IV.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2008-07-15·CVSS 7.1
CVE-2008-2826 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Linux kernel vulnerabilities
Dirk Nehring discovered that the IPsec protocol stack did not correctly
handle fragmented ESP packets. A remote attacker could exploit this to
crash the system, leading to a denial of service. (CVE-2007-6282)
Johannes Bauer discovered that the 64bit kernel did not correctly handle
hrtimer updates. A local attacker could request a large expiration value
and cause the system to hang, leading to a denial of service.
(CVE-2007-6712)
Tavis Ormandy discovered that the ia32 emulation under 64bit kernels did
not fully clear uninitialized data. A local attacker could read private
kernel memory, leading to a loss of privacy. (CVE-2008-0598)
Jan Kratochvil discovered that PTRACE did not correctly handle certain
calls when
Red Hat
IPSec ESP kernel panics
vendor_redhat·2008-02-22·CVSS 7.1
CVE-2007-6282 [HIGH] IPSec ESP kernel panics
IPSec ESP kernel panics
The IPsec implementation in Linux kernel before 2.6.25 allows remote routers to cause a denial of service (crash) via a fragmented ESP packet in which the first fragment does not contain the entire ESP header and IV.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2008-06/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-07/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-07/msg00002.htmlhttp://marc.info/?l=linux-netdev&m=120372380411259&w=2http://secunia.com/advisories/30112http://secunia.com/advisories/30294http://secunia.com/advisories/30818http://secunia.com/advisories/30890http://secunia.com/advisories/30962http://secunia.com/advisories/31107http://secunia.com/advisories/31551http://secunia.com/advisories/31628http://www.debian.org/security/2008/dsa-1630http://www.redhat.com/support/errata/RHSA-2008-0237.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0275.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0585.htmlhttp://www.securityfocus.com/bid/29081http://www.ubuntu.com/usn/usn-625-1https://bugzilla.redhat.com/show_bug.cgi?id=404291https://exchange.xforce.ibmcloud.com/vulnerabilities/42276https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10549http://lists.opensuse.org/opensuse-security-announce/2008-06/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-07/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-07/msg00002.htmlhttp://marc.info/?l=linux-netdev&m=120372380411259&w=2http://secunia.com/advisories/30112http://secunia.com/advisories/30294http://secunia.com/advisories/30818http://secunia.com/advisories/30890http://secunia.com/advisories/30962http://secunia.com/advisories/31107http://secunia.com/advisories/31551http://secunia.com/advisories/31628http://www.debian.org/security/2008/dsa-1630http://www.redhat.com/support/errata/RHSA-2008-0237.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0275.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0585.htmlhttp://www.securityfocus.com/bid/29081http://www.ubuntu.com/usn/usn-625-1https://bugzilla.redhat.com/show_bug.cgi?id=404291https://exchange.xforce.ibmcloud.com/vulnerabilities/42276https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10549
2008-05-08
Published