CVE-2005-3274

Severity CVSS v4.0:
Pending analysis
Type:
CWE-476 NULL Pointer Dereference
Publication date:
21/10/2005
Last modified:
03/04/2025

Description

Race condition in ip_vs_conn_flush in Linux 2.6 before 2.6.13 and 2.4 before 2.4.32-pre2, when running on SMP systems, allows local users to cause a denial of service (null dereference) by causing a connection timer to expire while the connection table is being flushed before the appropriate lock is acquired.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 2.4.0 (including) 2.4.31 (including)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 2.6.0 (including) 2.6.13 (excluding)
cpe:2.3:o:debian:debian_linux:3.1:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools