CVE-2012-2663

high
Published 2014-02-15 · Modified 2026-04-29
CVSS v3
CVSS v2
7.5
VIR risk
7.5

Description

extensions/libxt_tcp.c in iptables through 1.4.21 does not match TCP SYN+FIN packets in --syn rules, which might allow remote attackers to bypass intended firewall restrictions via crafted packets. NOTE: the CVE-2012-6638 fix makes this issue less relevant.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2012-2663

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://bugzilla.redhat.com/show_bug.cgi?id=826702

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://www.spinics.net/lists/netfilter-devel/msg21248.html

OS impact

OSVersionStatusFixed in
debian debianbookwormaffected
debian debianbullseyeaffected
debian debianforkyaffected
debian debiansidaffected
debian debiantrixieaffected

Application impact

VendorProductVersionsFixed
netfilteriptables{"endIncluding":"1.4.21"}

References

Verify integrity in audit chain (admin only). AS-IS.