CVE-2007-5501

Publication date 15 November 2007

Last updated 24 July 2024


Ubuntu priority

Negligible

Why this priority?

The tcp_sacktag_write_queue function in net/ipv4/tcp_input.c in Linux kernel 2.6.21 through 2.6.23.7, and 2.6.24-rc through 2.6.24-rc2, allows remote attackers to cause a denial of service (crash) via crafted ACK responses that trigger a NULL pointer dereference.

Read the notes from the security team

Status

Package Ubuntu Release Status
linux-source-2.6.22 7.10 gutsy
Not affected

Notes


kees

Ilpo Järvinen (original reporter) confirms that this is not actually exploitable

References

Related Ubuntu Security Notices (USN)

    • USN-574-1
    • Linux kernel vulnerabilities
    • 4 February 2008
    • USN-558-1
    • Linux kernel vulnerabilities
    • 19 December 2007

Other references