Security Advisory

CVE-2005-2456

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2005-08-04 04:00:00
Last updated 2024-08-07 22:30:01
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Array index overflow in the xfrm_sk_policy_insert function in xfrm_user.c in Linux kernel 2.6 allows local users to cause a denial of service (oops or deadlock) and possibly execute arbitrary code via a p->dir value that is larger than XFRM_POLICY_OUT, which is used as an index in the sock->sk_policy array.