Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
net/ipv6/addrconf.c in the IPv6 stack in the Linux kernel before 4.0 does not validate attempted changes to the MTU value, which allows context-dependent attackers to cause a denial of service (packet loss) via a value that is (1) smaller than the minimum compliant value or (2) larger than the MTU of an interface, as demonstrated by a Router Advertisement (RA) message that is not validated by a daemon, a different vulnerability than CVE-2015-0272. NOTE: the scope of CVE-2015-0272 is limited to the NetworkManager product.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Linux kernel IPv6栈输入验证错误漏洞
Vulnerability Description
Linux kernel是美国Linux基金会发布的开源操作系统Linux所使用的内核。NFSv4 implementation是其中的一个分布式文件系统协议。 Linux kernel 4.0之前版本的IPv6栈中的net/ipv6/addrconf.c文件存在安全漏洞,该漏洞源于程序没有检查新的‘MTU’值是否有效。攻击者可借助小于最小值或大于接口MTU(最大传输单元)的值利用该漏洞造成拒绝服务(数据包丢失)。
CVSS Information
N/A
Vulnerability Type
N/A