** Description changed: - panic while appending data to a corked IPv6 socket in - ip6_append_data_mtu + The ip6_append_data_mtu function in net/ipv6/ip6_output.c in the IPv6 + implementation in the Linux kernel through 3.10.3 does not properly + maintain information about whether the IPV6_MTU setsockopt option had + been specified, which allows local users to cause a denial of service + (BUG and system crash) via a crafted application that uses the UDP_CORK + option in a setsockopt system call. Break-Fix: 0c1833797a5a6ec23ea9261d979aa18078720b74 75a493e60ac4bbe2e977e7129d6d8cbb0dd236be
-- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1205078 Title: CVE-2013-4163 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1205078/+subscriptions -- ubuntu-bugs mailing list [email protected] https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
