Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 262303 (CVE-2009-0778) - Kernel: Dst entry leak in icmp_send host re-lookup code (v2). (CVE-2009-0778)
Summary: Kernel: Dst entry leak in icmp_send host re-lookup code (v2). (CVE-2009-0778)
Status: RESOLVED FIXED
Alias: CVE-2009-0778
Product: Gentoo Security
Classification: Unclassified
Component: Kernel (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL: http://git.kernel.org/?p=linux/kernel...
Whiteboard: [ linux <2.6.25 ]
Keywords:
Depends on:
Blocks:
 
Reported: 2009-03-12 20:56 UTC by Stefan Behte (RETIRED)
Modified: 2013-09-15 20:07 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Stefan Behte (RETIRED) gentoo-dev Security 2009-03-12 20:56:17 UTC
CVE-2009-0778 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-0778):
  The icmp_send function in net/ipv4/icmp.c in the Linux kernel before
  2.6.25, when configured as a router with a REJECT route, does not
  properly manage the Protocol Independent Destination Cache (aka DST)
  in some situations involving transmission of an ICMP Host Unreachable
  message, which allows remote attackers to cause a denial of service
  (connectivity outage) by sending a large series of packets to many
  destination IP addresses within this REJECT route, related to an
  "rt_cache leak."
Comment 1 kfm 2009-07-21 03:39:11 UTC
hardened-kernel unaffected at present time. Removing alias.