Vulnerability Description
Linux kernel 2.6.x, when using both NFS and EXT3, allows remote attackers to cause a denial of service (file system panic) via a crafted UDP packet with a V2 lookup procedure that specifies a bad file handle (inode number), which triggers an error and causes an exported directory to be remounted read-only.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | 2.6.0 |
References
- http://lkml.org/lkml/2006/7/17/41
- http://secunia.com/advisories/21369
- http://secunia.com/advisories/21605
- http://secunia.com/advisories/21614
- http://secunia.com/advisories/21847
- http://secunia.com/advisories/21934
- http://secunia.com/advisories/22093
- http://secunia.com/advisories/22148
- http://secunia.com/advisories/22174
- http://secunia.com/advisories/22822
- http://support.avaya.com/elmodocs2/security/ASA-2006-203.htm
- http://www.debian.org/security/2006/dsa-1184
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:150
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:151
- http://www.novell.com/linux/security/advisories/2006_21_sr.html
FAQ
What is CVE-2006-3468?
CVE-2006-3468 is a vulnerability with a CVSS score of 7.8 (HIGH). Linux kernel 2.6.x, when using both NFS and EXT3, allows remote attackers to cause a denial of service (file system panic) via a crafted UDP packet with a V2 lookup procedure that specifies a bad file...
How severe is CVE-2006-3468?
CVE-2006-3468 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2006-3468?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.