CVE-2007-2876

Publication date 11 June 2007

Last updated 24 July 2024


Ubuntu priority

The sctp_new function in (1) ip_conntrack_proto_sctp.c and (2) nf_conntrack_proto_sctp.c in Netfilter in Linux kernel 2.6 before 2.6.20.13, and 2.6.21.x before 2.6.21.4, allows remote attackers to cause a denial of service by causing certain invalid states that trigger a NULL pointer dereference.

Status

Package Ubuntu Release Status
linux-source-2.6.15 7.04 feisty Not in release
6.10 edgy Not in release
6.06 LTS dapper
Fixed 2.6.15-29.58
linux-source-2.6.17 7.04 feisty Not in release
6.10 edgy
Fixed 2.6.17.1-12.40
6.06 LTS dapper Not in release
linux-source-2.6.20 7.04 feisty
Fixed 2.6.20-16.31
6.10 edgy Not in release
6.06 LTS dapper Not in release
linux-source-2.6.22 7.04 feisty Not in release
6.10 edgy Not in release
6.06 LTS dapper Not in release

References

Related Ubuntu Security Notices (USN)

    • USN-510-1
    • Linux kernel vulnerabilities
    • 31 August 2007
    • USN-489-1
    • Linux kernel vulnerabilities
    • 19 July 2007
    • USN-486-1
    • Linux kernel vulnerabilities
    • 18 July 2007

Other references