CVE-2008-2136: High severity linux kernel vulnerability
Memory leak in the ipip6rcv function in net/ipv6/sit.c in the Linux kernel 2.4 before 2.4.36.5 and 2.6 before 2.6.25.3 allows remote attackers to cause a denial of service (memory consumption) via network traffic to a Simple Internet Transition (SIT) tunnel interface, related to the pskbmaypull and kfreeskb functions, and management of an skb reference count.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-2136?
CVE-2008-2136 has a medium severity rating as it allows remote attackers to cause denial of service through memory consumption.
How do I fix CVE-2008-2136?
To fix CVE-2008-2136, upgrade to Linux kernel version 2.4.36.5 or higher for the 2.4 series, or 2.6.25.3 or higher for the 2.6 series.
What software versions are affected by CVE-2008-2136?
CVE-2008-2136 affects Linux kernel versions prior to 2.4.36.5 and 2.6.25.3, along with specific versions of Debian and Ubuntu Linux.
Can CVE-2008-2136 be exploited remotely?
Yes, CVE-2008-2136 can be exploited remotely by sending crafted network traffic to a Simple Internet Transition (SIT) tunnel interface.
What impact does CVE-2008-2136 have on a system?
The impact of CVE-2008-2136 is denial of service, causing the affected system to experience memory leaks and potential crashes.