Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The ip6_append_data_mtu function in net/ipv6/ip6_output.c in the IPv6 implementation in the Linux kernel through 3.10.3 does not properly maintain information about whether the IPV6_MTU setsockopt option had been specified, which allows local users to cause a denial of service (BUG and system crash) via a crafted application that uses the UDP_CORK option in a setsockopt system call.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Linux Kernel 本地拒绝服务漏洞
Vulnerability Description
Linux kernel是美国Linux基金会发布的开源操作系统Linux所使用的内核。NFSv4 implementation是其中的一个分布式文件系统协议。 Linux内核3.10.3及之前的版本中的IPv6实现中的net/ipv6/ip6_output.c文件中的ip6_append_data_mtu函数中存在漏洞,该漏洞源于程序没有正确地维护关于IPV6_MTU setsockopt选项是否已被指定的信息。本地攻击者可通过在setsockopt系统调用中使用了UDP_CORK选项的应用程序利用该漏
CVSS Information
N/A
Vulnerability Type
N/A