Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2010-1188

Use-after-free vulnerability in net/ipv4/tcp_input.c in the Linux kernel 2.6 before 2.6.20, when IPV6_RECVPKTINFO is set on a listening socket, allows remote attackers to cause a denial of service (kernel panic) via a SYN packet while the socket is in a listening (TCP_LISTEN) state, which is not properly handled and causes the skb structure to be freed.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.027
EPSS Ranking 85.4%
CVSS Severity
CVSS v2 Score 7.1
References
Products affected by CVE-2010-1188


Contact Us

Shodan ® - All rights reserved