CVE-2011-2699Kernel vulnerability

17 documents6 sources
Severity
7.5HIGHNVD
EPSS
1.4%
top 19.82%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 24
Latest updateMay 13

Description

The IPv6 implementation in the Linux kernel before 3.1 does not generate Fragment Identification values separately for each destination, which makes it easier for remote attackers to cause a denial of service (disrupted networking) by predicting these values and sending crafted packets.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

Also affects: Enterprise Linux 4.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-69g3-qvqf-82hh: The IPv6 implementation in the Linux kernel before 32022-05-13
CVEList
CVE-2011-2699: The IPv6 implementation in the Linux kernel before 32012-05-24

📋Vendor Advisories

12
Ubuntu
Linux kernel (Natty backport) vulnerabilities2011-11-09
Ubuntu
Linux kernel vulnerabilities2011-11-08
Ubuntu
Linux kernel (EC2) vulnerabilities2011-10-25
Ubuntu
Linux kernel (Marvell DOVE) vulnerabilities2011-10-25
Ubuntu
Linux kernel vulnerabilities2011-10-11

💬Community

2
Bugzilla
CVE-2011-2699 kernel: ipv6: make fragment identifications less predictable [fedora-all]2011-10-25
Bugzilla
CVE-2011-2699 kernel: ipv6: make fragment identifications less predictable2011-07-20
CVE-2011-2699 — Linux Kernel vulnerability | cvebase