UBUNTU-CVE-2014-7207
Dashboard / Vulnerabilities / UBUNTU-CVE-2014-7207
UBUNTU-CVE-2014-7207
Summary:
Details: A certain Debian patch to the IPv6 implementation in the Linux kernel 3.2.x through 3.2.63 does not properly validate arguments in ipv6_select_ident function calls, which allows local users to cause a denial of service (NULL pointer dereference and system crash) by leveraging (1) tun or (2) macvtap device access.
References: https://ubuntu.com/security/CVE-2014-7207, https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=916e4cf46d0204806c062c8c6c4d1f633852c5b6, http://bugs.debian.org/766195, https://ubuntu.com/security/notices/USN-2417-1, https://ubuntu.com/security/notices/USN-2418-1, https://www.cve.org/CVERecord?id=CVE-2014-7207
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
