CVE-2005-3274

Race condition in ip_vs_conn_flush in Linux 2.6 before 2.6.13 and 2.4 before 2.4.32-pre2, when running on SMP systems, allows local users to cause a denial of service (null dereference) by causing a connection timer to expire while the connection table is being flushed before the appropriate lock is acquired.
References
Link Resource
http://lkml.org/lkml/2005/6/23/249 Mailing List Patch
http://lkml.org/lkml/2005/6/24/173 Mailing List Patch
http://secunia.com/advisories/17826 Broken Link
http://secunia.com/advisories/18056 Broken Link
http://secunia.com/advisories/18684 Broken Link
http://secunia.com/advisories/18977 Broken Link
http://www.debian.org/security/2005/dsa-922 Third Party Advisory
http://www.kernel.org/git/?p=linux/kernel/git/marcelo/linux-2.4.git%3Ba=commit%3Bh=e684f066dff5628bb61ad1912de6e8058b5b4c7d Patch
http://www.mandriva.com/security/advisories?name=MDKSA-2005:218 Patch Third Party Advisory
http://www.mandriva.com/security/advisories?name=MDKSA-2005:219 Patch Third Party Advisory
http://www.mandriva.com/security/advisories?name=MDKSA-2005:220 Patch Third Party Advisory
http://www.mandriva.com/security/advisories?name=MDKSA-2005:235 Patch Third Party Advisory
http://www.redhat.com/support/errata/RHSA-2005-663.html Broken Link
http://www.redhat.com/support/errata/RHSA-2006-0190.html Broken Link
http://www.securityfocus.com/archive/1/427980/100/0/threaded Broken Link Third Party Advisory VDB Entry
http://www.securityfocus.com/archive/1/427981/100/0/threaded Broken Link Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/15528 Broken Link Third Party Advisory VDB Entry
http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:044 Product
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11723 Broken Link
https://usn.ubuntu.com/219-1/ Broken Link
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:debian:debian_linux:3.1:*:*:*:*:*:*:*

History

21 Jan 2024, 01:26

Type Values Removed Values Added
CWE NVD-CWE-Other CWE-476
References (MANDRAKE) http://www.mandriva.com/security/advisories?name=MDKSA-2005:218 - (MANDRAKE) http://www.mandriva.com/security/advisories?name=MDKSA-2005:218 - Patch, Third Party Advisory
References (FEDORA) http://www.securityfocus.com/archive/1/427980/100/0/threaded - (FEDORA) http://www.securityfocus.com/archive/1/427980/100/0/threaded - Broken Link, Third Party Advisory, VDB Entry
References (BID) http://www.securityfocus.com/bid/15528 - (BID) http://www.securityfocus.com/bid/15528 - Broken Link, Third Party Advisory, VDB Entry
References (SECUNIA) http://secunia.com/advisories/18977 - (SECUNIA) http://secunia.com/advisories/18977 - Broken Link
References (CONFIRM) http://lkml.org/lkml/2005/6/24/173 - (CONFIRM) http://lkml.org/lkml/2005/6/24/173 - Mailing List, Patch
References (CONFIRM) http://lkml.org/lkml/2005/6/23/249 - (CONFIRM) http://lkml.org/lkml/2005/6/23/249 - Mailing List, Patch
References (MANDRIVA) http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:044 - (MANDRIVA) http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:044 - Product
References (FEDORA) http://www.securityfocus.com/archive/1/427981/100/0/threaded - (FEDORA) http://www.securityfocus.com/archive/1/427981/100/0/threaded - Broken Link, Third Party Advisory, VDB Entry
References (OVAL) https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11723 - (OVAL) https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11723 - Broken Link
References (SECUNIA) http://secunia.com/advisories/17826 - (SECUNIA) http://secunia.com/advisories/17826 - Broken Link
References (UBUNTU) https://usn.ubuntu.com/219-1/ - (UBUNTU) https://usn.ubuntu.com/219-1/ - Broken Link
References (SECUNIA) http://secunia.com/advisories/18684 - (SECUNIA) http://secunia.com/advisories/18684 - Broken Link
References (DEBIAN) http://www.debian.org/security/2005/dsa-922 - (DEBIAN) http://www.debian.org/security/2005/dsa-922 - Third Party Advisory
References (MANDRAKE) http://www.mandriva.com/security/advisories?name=MDKSA-2005:219 - (MANDRAKE) http://www.mandriva.com/security/advisories?name=MDKSA-2005:219 - Patch, Third Party Advisory
References (MANDRAKE) http://www.mandriva.com/security/advisories?name=MDKSA-2005:220 - (MANDRAKE) http://www.mandriva.com/security/advisories?name=MDKSA-2005:220 - Patch, Third Party Advisory
References () http://www.kernel.org/git/?p=linux/kernel/git/marcelo/linux-2.4.git%3Ba=commit%3Bh=e684f066dff5628bb61ad1912de6e8058b5b4c7d - () http://www.kernel.org/git/?p=linux/kernel/git/marcelo/linux-2.4.git%3Ba=commit%3Bh=e684f066dff5628bb61ad1912de6e8058b5b4c7d - Patch
References (SECUNIA) http://secunia.com/advisories/18056 - (SECUNIA) http://secunia.com/advisories/18056 - Broken Link
References (MANDRIVA) http://www.mandriva.com/security/advisories?name=MDKSA-2005:235 - (MANDRIVA) http://www.mandriva.com/security/advisories?name=MDKSA-2005:235 - Patch, Third Party Advisory
References (REDHAT) http://www.redhat.com/support/errata/RHSA-2005-663.html - (REDHAT) http://www.redhat.com/support/errata/RHSA-2005-663.html - Broken Link
References (REDHAT) http://www.redhat.com/support/errata/RHSA-2006-0190.html - (REDHAT) http://www.redhat.com/support/errata/RHSA-2006-0190.html - Broken Link
First Time Debian debian Linux
Debian
CVSS v2 : 1.2
v3 : unknown
v2 : 1.2
v3 : 4.7
CPE cpe:2.3:o:linux:linux_kernel:2.4.21:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.4.10:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12.6:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.4.7:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.10:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.3:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12.4:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.11.6:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.11.5:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.4.28:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.4.2:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.11.9:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.9:2.6.20:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.11.11:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.4.26:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.11:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.4.19:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.4.20:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.11.3:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12.1:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.4.3:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.4.24:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.4.4:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.11.4:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.6:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12.5:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.4.8:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.4.30:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.4.25:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.4.6:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12.2:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.5:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.11.2:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.11.12:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.2:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.8.1:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.4.23:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.7:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.0:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.4:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12.3:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.11.10:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.4.11:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.4.1:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.4.31:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.4.9:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.4.29:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.11.7:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.11.8:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.4.5:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.4.17:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.4.15:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.8:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.4.27:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.4.14:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.4.18:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.4.22:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.4.13:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.4.16:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.4.12:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.1:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.4.0:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.11.1:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:3.1:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

07 Nov 2023, 01:57

Type Values Removed Values Added
References
  • {'url': 'http://www.kernel.org/git/?p=linux/kernel/git/marcelo/linux-2.4.git;a=commit;h=e684f066dff5628bb61ad1912de6e8058b5b4c7d', 'name': 'http://www.kernel.org/git/?p=linux/kernel/git/marcelo/linux-2.4.git;a=commit;h=e684f066dff5628bb61ad1912de6e8058b5b4c7d', 'tags': ['Vendor Advisory'], 'refsource': 'CONFIRM'}
  • () http://www.kernel.org/git/?p=linux/kernel/git/marcelo/linux-2.4.git%3Ba=commit%3Bh=e684f066dff5628bb61ad1912de6e8058b5b4c7d -

Information

Published : 2005-10-21 01:02

Updated : 2024-02-28 10:42


NVD link : CVE-2005-3274

Mitre link : CVE-2005-3274

CVE.ORG link : CVE-2005-3274


JSON object : View

Products Affected

linux

  • linux_kernel

debian

  • debian_linux
CWE
CWE-476

NULL Pointer Dereference