From ef299f16878b2901bb7426ef3c716e10424f9686 Mon Sep 17 00:00:00 2001 From: dann frazier Date: Mon, 30 Apr 2007 23:07:13 +0000 Subject: retire CVE-2006-2446 git-svn-id: svn+ssh://svn.debian.org/svn/kernel-sec@784 e094ebfe-e918-0410-adfb-c712417f3574 --- retired/CVE-2006-2446 | 24 ++++++++++++++++++++++++ 1 file changed, 24 insertions(+) create mode 100644 retired/CVE-2006-2446 (limited to 'retired/CVE-2006-2446') diff --git a/retired/CVE-2006-2446 b/retired/CVE-2006-2446 new file mode 100644 index 00000000..d6e417d4 --- /dev/null +++ b/retired/CVE-2006-2446 @@ -0,0 +1,24 @@ +Candidate: CVE-2006-2446 +References: + REDHAT:RHSA-2006:0575 + URL:http://www.redhat.com/support/errata/RHSA-2006-0575.html + MISC:https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=192779 + SECUNIA:21465 + URL:http://secunia.com/advisories/21465 +Description: + Race condition between the kfree_skb and __skb_unlink functions in + the socket buffer handling in Linux kernel 2.6.9, and possibly other + versions, allows remote attackers to cause a denial of service + (crash), as demonstrated using the TCP stress tests from the LTP test + suite. +Ubuntu-Description: +Notes: +Bugs: +upstream: released (2.6.11) +linux-2.6: N/A +2.6.8-sarge-security: released (2.6.8-16sarge5) [kfree_skb-race.dpatch] +2.4.27-sarge-security: released (2.4.27-10sarge4) [227_kfree_skb.diff] +2.6.12-breezy-security: N/A +2.6.15-dapper-security: N/A +2.6.17-edgy: N/A +2.6.18-etch-security: N/A -- cgit v1.2.3