Description
The ipv4_pktinfo_prepare function in net/ipv4/ip_sockglue.c in the Linux kernel through 4.9.9 allows attackers to cause a denial of service (system crash) via (1) an application that makes crafted system calls or possibly (2) IPv4 traffic with invalid IP options. 7.5high (attack range: remote)
Patch available upstream.
file affected: kernel-adaptation-sbj-3.4.108.20161101.1/net/ipv4/ip_sockglue.c lines 1040-1046