UBUNTU-CVE-2015-8787
The nf_nat_redirect_ipv4 function in net/netfilter/nf_nat_redirect.c in the Linux kernel before 4.4 allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by sending certain IPv4 packets to an incompletely configured interface, a related issue to CVE-2003-1604.
02 / AFFECTED SOFTWARE
Affected packages
19 explicit affected versions
6 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
The nf_nat_redirect_ipv4 function in net/netfilter/nf_nat_redirect.c in the Linux kernel before 4.4 allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by sending certain IPv4 packets to an incompletely configured interface, a related issue to CVE-2003-1604.
05 / REFERENCES
Further evidence
- http://www.openwall.com/lists/oss-security/2016/01/27/6
- https://bugzilla.redhat.com/show_bug.cgi?id=1300731
- https://lkml.org/lkml/2015/12/2/618
- https://ubuntu.com/security/CVE-2015-8787
- https://ubuntu.com/security/notices/USN-2889-1
- https://ubuntu.com/security/notices/USN-2889-2
- https://ubuntu.com/security/notices/USN-2890-1
- https://ubuntu.com/security/notices/USN-2890-2
- https://ubuntu.com/security/notices/USN-2890-3
- https://www.cve.org/CVERecord?id=CVE-2015-8787