Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:18243
HistoryMay 02, 2019 - 6:36 a.m.

Denial Of Service (DOS)

2019-05-0206:36:12
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8

0.0004 Low

EPSS

Percentile

15.7%

Linux kernel is vulnerable to denial of service (DOS) attacks. The vulnerability exists because the ping_unhash function in net/ipv4/ping.c in the Linux kernel is too late in obtaining a certain lock and consequently cannot ensure that disconnect function calls are safe. Local attackers with access to ping sockets could use this flaw to crash the system by leveraging access to the protocol value of IPPROTO_ICMP in a socket system call…

References