CVE-2015-2924: Input Validation
The receivera function in rdisc/nm-lndp-rdisc.c in the Neighbor Discovery (ND) protocol implementation in the IPv6 stack in NetworkManager 1.x allows remote attackers to reconfigure a hop-limit setting via a small hoplimit value in a Router Advertisement (RA) message, a similar issue to CVE-2015-2922.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2924?
CVE-2015-2924 is classified as a high-severity vulnerability due to its potential impact on network configuration and security.
How do I fix CVE-2015-2924?
To fix CVE-2015-2924, update NetworkManager to a version later than 1.0.7 that addresses this vulnerability.
What systems are affected by CVE-2015-2924?
CVE-2015-2924 affects NetworkManager versions up to and including 1.0.7 on systems using the IPv6 stack.
What is the impact of CVE-2015-2924?
The impact of CVE-2015-2924 allows remote attackers to alter the hop-limit settings, potentially disrupting network operations.
Is CVE-2015-2924 being actively exploited?
As of now, there are no widely reported cases of CVE-2015-2924 being actively exploited in the wild.