CVE-2014-7207 REJECTED

A certain Debian patch to the IPv6 implementation in the Linux kernel 3.2.x through 3.2.63 does not properly validate arguments in ipv6_select_ident function calls, which allows local users to cause a denial of service (NULL pointer dereference and system crash) by leveraging (1) tun or (2) macvtap device access.

EPSS 0.09% · 24.9th percentile

Risk Scores

EPSS Score
0.09%
24.9th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSlinux-lts-vivid0
Ubuntu:14.04:LTSlinux3.11.0-12.19, 3.12.0-1.3, 3.12.0-2.5
Ubuntu:14.04:LTSlinux-lts-utopic0

Timeline

References

Open in Interactive Console →