CVE-2008-2136
published 2008-05-16CVE-2008-2136: Memory leak in the ipip6_rcv function in net/ipv6/sit.c in the Linux kernel 2.4 before 2.4.36.5 and 2.6 before 2.6.25.3 allows remote attackers to cause a…
PriorityP432high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
4.93%
91.3th percentile
Memory leak in the ipip6_rcv function in net/ipv6/sit.c in the Linux kernel 2.4 before 2.4.36.5 and 2.6 before 2.6.25.3 allows remote attackers to cause a denial of service (memory consumption) via network traffic to a Simple Internet Transition (SIT) tunnel interface, related to the pskb_may_pull and kfree_skb functions, and management of an skb reference count.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| linux | linux_kernel | >= 2.4.0 < 2.4.36.5 | 2.4.36.5 |
| linux | linux_kernel | >= 2.6.0 < 2.6.25.3 | 2.6.25.3 |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_redhat7.8HIGH
vendor_ubuntu7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2008-07-15·CVSS 7.1
CVE-2008-2826 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Linux kernel vulnerabilities
Dirk Nehring discovered that the IPsec protocol stack did not correctly
handle fragmented ESP packets. A remote attacker could exploit this to
crash the system, leading to a denial of service. (CVE-2007-6282)
Johannes Bauer discovered that the 64bit kernel did not correctly handle
hrtimer updates. A local attacker could request a large expiration value
and cause the system to hang, leading to a denial of service.
(CVE-2007-6712)
Tavis Ormandy discovered that the ia32 emulation under 64bit kernels did
not fully clear uninitialized data. A local attacker could read private
kernel memory, leading to a loss of privacy. (CVE-2008-0598)
Jan Kratochvil discovered that PTRACE did not correctly handle certain
calls when
Red Hat
kernel: sit memory leak
vendor_redhat·2008-05-09·CVSS 7.8
CVE-2008-2136 [HIGH] CWE-401 kernel: sit memory leak
kernel: sit memory leak
Memory leak in the ipip6_rcv function in net/ipv6/sit.c in the Linux kernel 2.4 before 2.4.36.5 and 2.6 before 2.6.25.3 allows remote attackers to cause a denial of service (memory consumption) via network traffic to a Simple Internet Transition (SIT) tunnel interface, related to the pskb_may_pull and kfree_skb functions, and management of an skb reference count.
GHSA
GHSA-cwpr-29v4-4jhw: Memory leak in the ipip6_rcv function in net/ipv6/sit
ghsa_unreviewed·2022-05-01
CVE-2008-2136 [HIGH] GHSA-cwpr-29v4-4jhw: Memory leak in the ipip6_rcv function in net/ipv6/sit
Memory leak in the ipip6_rcv function in net/ipv6/sit.c in the Linux kernel 2.4 before 2.4.36.5 and 2.6 before 2.6.25.3 allows remote attackers to cause a denial of service (memory consumption) via network traffic to a Simple Internet Transition (SIT) tunnel interface, related to the pskb_may_pull and kfree_skb functions, and management of an skb reference count.
No detection rules found.
No public exploits indexed.
http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.25.3http://lists.opensuse.org/opensuse-security-announce/2008-06/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-07/msg00002.htmlhttp://marc.info/?l=linux-netdev&m=121031533024912&w=2http://secunia.com/advisories/30198http://secunia.com/advisories/30241http://secunia.com/advisories/30276http://secunia.com/advisories/30368http://secunia.com/advisories/30499http://secunia.com/advisories/30818http://secunia.com/advisories/30962http://secunia.com/advisories/31107http://secunia.com/advisories/31198http://secunia.com/advisories/31341http://secunia.com/advisories/31628http://secunia.com/advisories/31689http://secunia.com/advisories/33201http://secunia.com/advisories/33280http://support.avaya.com/elmodocs2/security/ASA-2008-362.htmhttp://wiki.rpath.com/wiki/Advisories:rPSA-2008-0169http://www.debian.org/security/2008/dsa-1588http://www.kernel.org/pub/linux/kernel/v2.4/ChangeLog-2.4.36.5http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.25.3http://www.mandriva.com/security/advisories?name=MDVSA-2008:167http://www.mandriva.com/security/advisories?name=MDVSA-2008:174http://www.redhat.com/support/errata/RHSA-2008-0585.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0607.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0612.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0787.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0973.htmlhttp://www.securityfocus.com/bid/29235http://www.securitytracker.com/id?1020118http://www.ubuntu.com/usn/usn-625-1http://www.vupen.com/english/advisories/2008/1543/referenceshttp://www.vupen.com/english/advisories/2008/1716/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/42451https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11038https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6503https://www.redhat.com/archives/fedora-package-announce/2008-May/msg00294.htmlhttp://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.25.3http://lists.opensuse.org/opensuse-security-announce/2008-06/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-07/msg00002.htmlhttp://marc.info/?l=linux-netdev&m=121031533024912&w=2http://secunia.com/advisories/30198http://secunia.com/advisories/30241http://secunia.com/advisories/30276http://secunia.com/advisories/30368http://secunia.com/advisories/30499http://secunia.com/advisories/30818http://secunia.com/advisories/30962http://secunia.com/advisories/31107http://secunia.com/advisories/31198http://secunia.com/advisories/31341http://secunia.com/advisories/31628http://secunia.com/advisories/31689http://secunia.com/advisories/33201http://secunia.com/advisories/33280http://support.avaya.com/elmodocs2/security/ASA-2008-362.htmhttp://wiki.rpath.com/wiki/Advisories:rPSA-2008-0169http://www.debian.org/security/2008/dsa-1588http://www.kernel.org/pub/linux/kernel/v2.4/ChangeLog-2.4.36.5http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.25.3http://www.mandriva.com/security/advisories?name=MDVSA-2008:167http://www.mandriva.com/security/advisories?name=MDVSA-2008:174http://www.redhat.com/support/errata/RHSA-2008-0585.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0607.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0612.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0787.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0973.htmlhttp://www.securityfocus.com/bid/29235http://www.securitytracker.com/id?1020118http://www.ubuntu.com/usn/usn-625-1http://www.vupen.com/english/advisories/2008/1543/referenceshttp://www.vupen.com/english/advisories/2008/1716/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/42451https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11038https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6503https://www.redhat.com/archives/fedora-package-announce/2008-May/msg00294.html
2008-05-16
Published