The ip6gre_err function in net/ipv6/ip6_gre.c in the Linux kernel allows remote attackers to have unspecified impact via vectors involving GRE flags in an IPv6 packet, which trigger an out-of-bounds access.
The product reads data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
http://www.securitytracker.com/id/1037794 | vdb entry third party advisory |
http://www.securityfocus.com/bid/96037 | vdb entry third party advisory |
https://source.android.com/security/bulletin/2017-09-01 | third party advisory |
https://git.kernel.org/pub/scm/linux/kernel/git/davem/net.git/commit/?id=7892032cfe67f4bde6fc2ee967e45a8fbaf33756 | third party advisory patch |
https://usn.ubuntu.com/3754-1/ | third party advisory vendor advisory |
http://www.openwall.com/lists/oss-security/2017/02/07/2 | third party advisory mailing list |
http://www.debian.org/security/2017/dsa-3791 | third party advisory vendor advisory |