CVE-2014-0100 REJECTED

Race condition in the inet_frag_intern function in net/ipv4/inet_fragment.c in the Linux kernel through 3.13.6 allows remote attackers to cause a denial of service (use-after-free error) or possibly have unspecified other impact via a large series of fragmented ICMP Echo Request packets to a system with a heavy CPU load.

EPSS 0.50% · 65.6th percentile

Risk Scores

EPSS Score
0.50%
65.6th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSlinux-raspi20
Ubuntu:16.04:LTSlinux0
Ubuntu:14.04:LTSlinux3.12.0-1.3, 3.12.0-2.5, 3.12.0-2.7
Ubuntu:16.04:LTSlinux-snapdragon0
Ubuntu:14.04:LTSlinux-lts-wily0
Ubuntu:14.04:LTSlinux-lts-xenial0
Ubuntu:16.04:LTSlinux-aws0
Ubuntu:14.04:LTSlinux-lts-vivid0
Ubuntu:16.04:LTSlinux-gke0
Ubuntu:14.04:LTSlinux-aws0
Ubuntu:14.04:LTSlinux-lts-utopic0
Ubuntu:16.04:LTSlinux-hwe0

Timeline

References

Open in Interactive Console →