UDP: Linux Kernel ipv4_pktinfo_prepare Denial of Service

A denial-of-service vulnerability has been reported in the Linux Kernel. Successful exploitation will cause a NULL pointer dereference, leading to a denial-of-service condition.

Extended Description

The ipv4_pktinfo_prepare function in net/ipv4/ip_sockglue.c in the Linux kernel through 4.9.9 allows attackers to cause a denial of service (system crash) via (1) an application that makes crafted system calls or possibly (2) IPv4 traffic with invalid IP options.

Affected Products

Linux linux_kernel

References

CVE: CVE-2017-5970

Short Name
UDP:CVE-2017-5970-DOS
Severity
Major
Recommended
True
Recommended Action
Drop
Category
UDP
Keywords
CVE-2017-5970 Denial Kernel Linux Service ipv4_pktinfo_prepare of
Release Date
04/11/2017
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3337
Port
UDP/12345
False Positive
Unknown
Vendors

Linux

CVSS Score

5.0

Found a potential security threat?