CVE-2011-4326
Publication date 23 November 2011
Last updated 24 July 2024
Ubuntu priority
The udp6_ufo_fragment function in net/ipv6/udp.c in the Linux kernel before 2.6.39, when a certain UDP Fragmentation Offload (UFO) configuration is enabled, allows remote attackers to cause a denial of service (system crash) by sending fragmented IPv6 UDP packets to a bridge device.
From the Ubuntu Security Team
A bug was found in the way headroom check was performed in udp6_ufo_fragment() function. A remote attacker could use this flaw to crash the system.
Status
Package | Ubuntu Release | Status |
---|---|---|
linux | ||
14.04 LTS trusty |
Not affected
|
|
linux-armadaxp | ||
14.04 LTS trusty | Not in release | |
linux-ec2 | ||
14.04 LTS trusty | Not in release | |
linux-flo | ||
14.04 LTS trusty | Not in release | |
linux-fsl-imx51 | ||
14.04 LTS trusty | Not in release | |
linux-goldfish | ||
14.04 LTS trusty | Not in release | |
linux-grouper | ||
14.04 LTS trusty | Not in release | |
linux-lts-backport-maverick | ||
14.04 LTS trusty | Not in release | |
linux-lts-backport-natty | ||
14.04 LTS trusty | Not in release | |
linux-lts-backport-oneiric | ||
14.04 LTS trusty | Not in release | |
linux-lts-quantal | ||
14.04 LTS trusty | Not in release | |
linux-lts-raring | ||
14.04 LTS trusty | Not in release | |
linux-lts-saucy | ||
14.04 LTS trusty | Not in release | |
linux-lts-trusty | ||
14.04 LTS trusty | Not in release | |
linux-lts-utopic | ||
14.04 LTS trusty | Not in release | |
linux-lts-vivid | ||
14.04 LTS trusty | Not in release | |
linux-maguro | ||
14.04 LTS trusty | Not in release | |
linux-mako | ||
14.04 LTS trusty | Not in release | |
linux-manta | ||
14.04 LTS trusty | Not in release | |
linux-mvl-dove | ||
14.04 LTS trusty | Not in release | |
linux-raspi2 | ||
14.04 LTS trusty | Not in release | |
linux-ti-omap4 | ||
14.04 LTS trusty | Not in release | |
References
Related Ubuntu Security Notices (USN)
- USN-1292-1
- Linux kernel (Maverick backport) vulnerabilities
- 8 December 2011
- USN-1294-1
- Linux kernel (Oneiric backport) vulnerabilities
- 8 December 2011
- USN-1302-1
- Linux kernel (OMAP4) vulnerabilities
- 13 December 2011
- USN-1299-1
- Linux kernel (EC2) vulnerabilities
- 13 December 2011
- USN-1303-1
- Linux kernel (Marvell DOVE) vulnerabilities
- 13 December 2011
- USN-1293-1
- Linux kernel vulnerabilities
- 8 December 2011
- USN-1311-1
- Linux kernel vulnerabilities
- 19 December 2011
- USN-1304-1
- Linux kernel (OMAP4) vulnerabilities
- 13 December 2011
- USN-1256-1
- Linux kernel (Natty backport) vulnerabilities
- 9 November 2011
- USN-1193-1
- Linux kernel vulnerabilities
- 19 August 2011