The netfilter subsystem in the Linux kernel before 4.9 mishandles IPv6 reassembly, which allows local users to cause a denial of service (integer overflow, out-of-bounds write, and GPF) or possibly have unspecified other impact via a crafted application that makes socket, connect, and writev system calls, related to net/ipv6/netfilter/nf_conntrack_reasm.c and net/ipv6/netfilter/nf_defrag_ipv6_hooks.c.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T02:59:03.563Z
Reserved: 2016-12-01T00:00:00
Link: CVE-2016-9755

No data.

Status : Deferred
Published: 2016-12-28T07:59:00.430
Modified: 2025-04-12T10:46:40.837
Link: CVE-2016-9755
