CVE-2012-2744
published 2012-08-09CVE-2012-2744: net/ipv6/netfilter/nf_conntrack_reasm.c in the Linux kernel before 2.6.34, when the nf_conntrack_ipv6 module is enabled, allows remote attackers to cause a…
PriorityP434high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
4.43%
90.4th percentile
net/ipv6/netfilter/nf_conntrack_reasm.c in the Linux kernel before 2.6.34, when the nf_conntrack_ipv6 module is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) via certain types of fragmented IPv6 packets.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 2.6.34-1 (bookworm) | linux 2.6.34-1 (bookworm) |
| linux | linux_kernel | <= 2.6.33.20 | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 2.6.34-1 | 2.6.34-1 |
| linux | linux_kernel | >= 0 < 2.6.34-1 | 2.6.34-1 |
| linux | linux_kernel | >= 0 < 2.6.34-1 | 2.6.34-1 |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rf7q-2943-h3jp: net/ipv6/netfilter/nf_conntrack_reasm
ghsa_unreviewed·2022-05-17
CVE-2012-2744 [HIGH] GHSA-rf7q-2943-h3jp: net/ipv6/netfilter/nf_conntrack_reasm
net/ipv6/netfilter/nf_conntrack_reasm.c in the Linux kernel before 2.6.34, when the nf_conntrack_ipv6 module is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) via certain types of fragmented IPv6 packets.
OSV
CVE-2012-2744: net/ipv6/netfilter/nf_conntrack_reasm
osv·2012-08-09·CVSS 7.8
CVE-2012-2744 [HIGH] CVE-2012-2744: net/ipv6/netfilter/nf_conntrack_reasm
net/ipv6/netfilter/nf_conntrack_reasm.c in the Linux kernel before 2.6.34, when the nf_conntrack_ipv6 module is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) via certain types of fragmented IPv6 packets.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2012-07-17·CVSS 4.9
CVE-2012-2744 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was found in the Linux kernel's KVM (Kernel Virtual Machine) virtual
cpu setup. An unprivileged local user could exploit this flaw to crash the
system leading to a denial of service. (CVE-2012-1601)
An error was found in the Linux kernel's IPv6 netfilter when connection
tracking is enabled. A remote attacker could exploit this flaw to crash a
system if it is using IPv6 with the nf_contrack_ipv6 kernel module loaded.
(CVE-2012-2744)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinsta
Red Hat
kernel: netfilter: null pointer dereference in nf_ct_frag6_reasm()
vendor_redhat·2012-07-10·CVSS 7.8
CVE-2012-2744 [HIGH] CWE-228 kernel: netfilter: null pointer dereference in nf_ct_frag6_reasm()
kernel: netfilter: null pointer dereference in nf_ct_frag6_reasm()
net/ipv6/netfilter/nf_conntrack_reasm.c in the Linux kernel before 2.6.34, when the nf_conntrack_ipv6 module is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) via certain types of fragmented IPv6 packets.
Statement: This issue did not affect the versions of the Linux kernel as shipped with Red Hat Enterprise Linux 5 as they did not include support for netfilter's ipv6 connection tracking module. This issue did not affect the versions of the Linux kernel as shipped with Red Hat Enterprise Linux MRG as they already contain the upstream commit that fixes this issue.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: realtime-kernel (Red Hat Enterp
Debian
CVE-2012-2744: linux - net/ipv6/netfilter/nf_conntrack_reasm.c in the Linux kernel before 2.6.34, when ...
vendor_debian·2012·CVSS 7.8
CVE-2012-2744 [HIGH] CVE-2012-2744: linux - net/ipv6/netfilter/nf_conntrack_reasm.c in the Linux kernel before 2.6.34, when ...
net/ipv6/netfilter/nf_conntrack_reasm.c in the Linux kernel before 2.6.34, when the nf_conntrack_ipv6 module is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) via certain types of fragmented IPv6 packets.
Scope: local
bookworm: resolved (fixed in 2.6.34-1)
bullseye: resolved (fixed in 2.6.34-1)
forky: resolved (fixed in 2.6.34-1)
sid: resolved (fixed in 2.6.34-1)
trixie: resolved (fixed in 2.6.34-1)
No detection rules found.
No public exploits indexed.
http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.34http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=9e2dcf72023d1447f09c47d77c99b0c49659e5cehttp://rhn.redhat.com/errata/RHSA-2012-1064.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1148.htmlhttp://secunia.com/advisories/49928http://www.securityfocus.com/bid/54367http://www.securitytracker.com/id?1027235https://bugzilla.redhat.com/show_bug.cgi?id=833402https://github.com/torvalds/linux/commit/9e2dcf72023d1447f09c47d77c99b0c49659e5cehttp://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.34http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=9e2dcf72023d1447f09c47d77c99b0c49659e5cehttp://rhn.redhat.com/errata/RHSA-2012-1064.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1148.htmlhttp://secunia.com/advisories/49928http://www.securityfocus.com/bid/54367http://www.securitytracker.com/id?1027235https://bugzilla.redhat.com/show_bug.cgi?id=833402https://github.com/torvalds/linux/commit/9e2dcf72023d1447f09c47d77c99b0c49659e5ce
2012-08-09
Published