REDHAT-BUG-2364090: Integer Overflow
ping in iputils through 20240905 allows a denial of service (application error or incorrect data collection) via a crafted ICMP Echo Reply packet, because of a signed 64-bit integer overflow in timestamp multiplication.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2364090?
The severity of REDHAT-BUG-2364090 is classified as a denial of service vulnerability due to an application error caused by a crafted ICMP Echo Reply packet.
How do I fix REDHAT-BUG-2364090?
To fix REDHAT-BUG-2364090, update to a version of iputils ping that is later than 20240905.
What causes the vulnerability REDHAT-BUG-2364090?
The vulnerability REDHAT-BUG-2364090 is caused by a signed 64-bit integer overflow during timestamp multiplication.
What systems are affected by REDHAT-BUG-2364090?
Systems running iputils ping versions up to and including 20240905 are affected by REDHAT-BUG-2364090.
Is there a workaround for REDHAT-BUG-2364090?
Currently, there are no documented workarounds for REDHAT-BUG-2364090; the recommended action is to apply the appropriate update.