Article Title: kernel malformed ULE DoS Vulnerability. Linux is a technology channel of the IT lab in China. Includes basic categories such as desktop applications, Linux system management, kernel research, embedded systems, and open source.
Affected Systems:
Linux kernel 2.6.x <= 2.6.17.7
Unaffected system:
Linux kernel 2.6.17.8
Description:
--------------------------------------------------------------------------------
Bugtraq id: 19939
CVE (CAN) ID: CVE-2006-4623
Linux Kernel is the Kernel used by open source Linux.
A vulnerability exists in Linux ULE (one-way lightweight encapsulation RFC 4326) code. Remote attackers may exploit this vulnerability to cause denial-of-service (DoS) attacks on servers that receive and process the code.
Attackers can trigger the vulnerability by sending a ULE message with a SNDU length of 0.
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Linux
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage: