vendor:
Linux Kernel
by:
SecurityFocus
7.8
CVSS
HIGH
Remote Denial of Service
399
CWE
Product Name: Linux Kernel
Affected Version From: 2.6.14.4
Affected Version To: 2.6.17.7
Patch Exists: YES
Related CWE: CVE-2006-2451
CPE: o:linux:linux_kernel
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2006
Linux Kernel EXT3 Filesystem Remote Denial of Service Vulnerability
The Linux kernel is susceptible to a remote denial-of-service vulnerability because the EXT3 filesystem code fails to properly handle unexpected conditions. Remote attackers may trigger this issue by sending crafted UDP datagrams to affected computers that are configured as NFS servers, causing filesystem errors. Depending on the mount-time options of affected filesystems, this may result in remounting filesystems as read-only or cause a kernel panic.
Mitigation:
Users should upgrade to the latest version of the Linux kernel to mitigate this vulnerability.