CVE-2016-2070
published 2016-05-02CVE-2016-2070: The tcp_cwnd_reduction function in net/ipv4/tcp_input.c in the Linux kernel before 4.3.5 allows remote attackers to cause a denial of service (divide-by-zero…
PriorityP337high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
3.32%
87.4th percentile
The tcp_cwnd_reduction function in net/ipv4/tcp_input.c in the Linux kernel before 4.3.5 allows remote attackers to cause a denial of service (divide-by-zero error and system crash) via crafted TCP traffic.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.3.5-1 (bookworm) | linux 4.3.5-1 (bookworm) |
| linux | linux_kernel | >= 0 < 4.3.5-1 | 4.3.5-1 |
| linux | linux_kernel | >= 0 < 4.3.5-1 | 4.3.5-1 |
| linux | linux_kernel | >= 0 < 4.3.5-1 | 4.3.5-1 |
| linux | linux_kernel | >= 0 < 4.3.5-1 | 4.3.5-1 |
| linux | linux_kernel | >= 4.3 < 4.3.5 | 4.3.5 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2016-2070: linux - The tcp_cwnd_reduction function in net/ipv4/tcp_input.c in the Linux kernel befo...
vendor_debian·2016·CVSS 7.5
CVE-2016-2070 [HIGH] CVE-2016-2070: linux - The tcp_cwnd_reduction function in net/ipv4/tcp_input.c in the Linux kernel befo...
The tcp_cwnd_reduction function in net/ipv4/tcp_input.c in the Linux kernel before 4.3.5 allows remote attackers to cause a denial of service (divide-by-zero error and system crash) via crafted TCP traffic.
Scope: local
bookworm: resolved (fixed in 4.3.5-1)
bullseye: resolved (fixed in 4.3.5-1)
forky: resolved (fixed in 4.3.5-1)
sid: resolved (fixed in 4.3.5-1)
trixie: resolved (fixed in 4.3.5-1)
Red Hat
kernel: potential division by zero in TCP code
vendor_redhat·2015-12-21·CVSS 7.5
CVE-2016-2070 [HIGH] CWE-369 kernel: potential division by zero in TCP code
kernel: potential division by zero in TCP code
The tcp_cwnd_reduction function in net/ipv4/tcp_input.c in the Linux kernel before 4.3.5 allows remote attackers to cause a denial of service (divide-by-zero error and system crash) via crafted TCP traffic.
A divide-by-zero vulnerability was found in a way the kernel processes TCP connections. The error can occur if a connection starts another cwnd reduction phase by setting tp->prior_cwnd to the current cwnd (0) in tcp_init_cwnd_reduction(). A remote, unauthenticated attacker could use this flaw to crash the kernel (denial of service).
Statement: This issue does not affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 5, 6, 7 and MRG-2 as the code with the flaw is not present in the products listed.
Package: kernel (R
GHSA
GHSA-fq7q-rch4-j8hq: The tcp_cwnd_reduction function in net/ipv4/tcp_input
ghsa_unreviewed·2022-05-17
CVE-2016-2070 [HIGH] GHSA-fq7q-rch4-j8hq: The tcp_cwnd_reduction function in net/ipv4/tcp_input
The tcp_cwnd_reduction function in net/ipv4/tcp_input.c in the Linux kernel before 4.3.5 allows remote attackers to cause a denial of service (divide-by-zero error and system crash) via crafted TCP traffic.
OSV
CVE-2016-2070: The tcp_cwnd_reduction function in net/ipv4/tcp_input
osv·2016-05-02·CVSS 7.5
CVE-2016-2070 [HIGH] CVE-2016-2070: The tcp_cwnd_reduction function in net/ipv4/tcp_input
The tcp_cwnd_reduction function in net/ipv4/tcp_input.c in the Linux kernel before 4.3.5 allows remote attackers to cause a denial of service (divide-by-zero error and system crash) via crafted TCP traffic.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-2070 kernel: potential division by zero in TCP code [fedora-all]
bugzilla·2016-01-28·CVSS 7.5
CVE-2016-2070 [HIGH] CVE-2016-2070 kernel: potential division by zero in TCP code [fedora-all]
CVE-2016-2070 kernel: potential division by zero in TCP code [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedo
Bugzilla
CVE-2016-2070 kernel: potential division by zero in TCP code
bugzilla·2016-01-27·CVSS 7.5
CVE-2016-2070 [HIGH] CVE-2016-2070 kernel: potential division by zero in TCP code
CVE-2016-2070 kernel: potential division by zero in TCP code
A divide-by-zero vulnerability was found in a way the kernel processes TCP connections. The error can occur if a connection starts another cwnd reduction phase by setting tp->prior_cwnd to the current cwnd (0) in tcp_init_cwnd_reduction(). A remote, unauthenticated attacker could use this flaw to crash the kernel (denial of service).
Original bug report:
https://lkml.org/lkml/2015/12/21/435
Oss-security reference:
http://seclists.org/oss-sec/2016/q1/198
CVE assignment:
http://seclists.org/oss-sec/2016/q1/211
Upstream fix:
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=8b8a321ff72c785ed5e8b4cf6eda20b35d427390
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 13
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=8b8a321ff72c785ed5e8b4cf6eda20b35d427390http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.3.5http://www.openwall.com/lists/oss-security/2016/01/25/5https://bugzilla.redhat.com/show_bug.cgi?id=1302219https://github.com/torvalds/linux/commit/8b8a321ff72c785ed5e8b4cf6eda20b35d427390http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=8b8a321ff72c785ed5e8b4cf6eda20b35d427390http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.3.5http://www.openwall.com/lists/oss-security/2016/01/25/5https://bugzilla.redhat.com/show_bug.cgi?id=1302219https://github.com/torvalds/linux/commit/8b8a321ff72c785ed5e8b4cf6eda20b35d427390
2016-05-02
Published