CVE-2015-6496
medium
CVSS v3
โ
CVSS v4 NEW
โ
VIR risk
5.0
Description
conntrackd in conntrack-tools 1.4.2 and earlier does not ensure that the optional kernel modules are loaded before using them, which allows remote attackers to cause a denial of service (crash) via a (1) DCCP, (2) SCTP, or (3) ICMPv6 packet.
Predictions
Exploit likelihood
20%
Patch ETA
โ
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| debian | 7.0 | affected | |
| debian | 8.0 | affected | |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| netfilter | conntrack-tools | {"endIncluding":"1.4.2"} | |
References
- http://bugzilla.netfilter.org/show_bug.cgi?id=910
- http://lists.fedoraproject.org/pipermail/package-announce/2016-January/174875.html
- http://lists.fedoraproject.org/pipermail/package-announce/2016-January/174883.html
- http://lists.opensuse.org/opensuse-updates/2015-10/msg00015.html
- http://www.debian.org/security/2015/dsa-3341
- http://www.openwall.com/lists/oss-security/2015/08/14/4
- http://www.openwall.com/lists/oss-security/2015/08/18/1
- https://git.netfilter.org/conntrack-tools/commit/?id=c392c159605956c7bd4a264ab4490e2b2704c0cd
- http://bugzilla.netfilter.org/show_bug.cgi?id=910
- http://lists.fedoraproject.org/pipermail/package-announce/2016-January/174875.html
- http://lists.fedoraproject.org/pipermail/package-announce/2016-January/174883.html
- http://lists.opensuse.org/opensuse-updates/2015-10/msg00015.html
- http://www.debian.org/security/2015/dsa-3341
- http://www.openwall.com/lists/oss-security/2015/08/14/4
- http://www.openwall.com/lists/oss-security/2015/08/18/1
- https://git.netfilter.org/conntrack-tools/commit/?id=c392c159605956c7bd4a264ab4490e2b2704c0cd
CWEs
CWE-17
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.