>> Linux Kernel "rt6_fill_node()" Local Denial of Service Vulnerability
Title : Linux Kernel "rt6_fill_node()" Local Denial of Service Vulnerability VUPEN ID : VUPEN/ADV-2008-2422 CVE ID : CVE-2008-3686 CWE ID : CWE-476
Rated as : Low Risk
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2008-08-25
Technical Description
A vulnerability has been identified in Linux Kernel, which could be exploited by local attackers to cause a denial of service. This issue is caused by a NULL pointer dereference error in the "rt6_fill_node()" [net/ipv6/route.c] function when no IPv6 input device is in use, which could allow malicious users to panic a vulnerable system via a specially crafted command, creating a denial of service condition.