CVE-2009-1298

Publication date 9 December 2009

Last updated 24 July 2024


Ubuntu priority

The ip_frag_reasm function in net/ipv4/ip_fragment.c in the Linux kernel 2.6.32-rc8, and 2.6.29 and later versions before 2.6.32, calls IP_INC_STATS_BH with an incorrect argument, which allows remote attackers to cause a denial of service (NULL pointer dereference and hang) via long IP packets, possibly related to the ip_defrag function.

Status

Package Ubuntu Release Status
linux 9.10 karmic
Fixed 2.6.31-16.53
9.04 jaunty
Not affected
8.10 intrepid
Not affected
8.04 LTS hardy
Not affected
6.06 LTS dapper Not in release
linux-source-2.6.15 9.10 karmic Not in release
9.04 jaunty Not in release
8.10 intrepid Not in release
8.04 LTS hardy Not in release
6.06 LTS dapper
Not affected

References

Related Ubuntu Security Notices (USN)

    • USN-869-1
    • Linux kernel vulnerabilities
    • 10 December 2009

Other references