CVE-2017-13715

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
29/08/2017
Last modified:
20/04/2025

Description

The __skb_flow_dissect function in net/core/flow_dissector.c in the Linux kernel before 4.3 does not ensure that n_proto, ip_proto, and thoff are initialized, which allows remote attackers to cause a denial of service (system crash) or possibly execute arbitrary code via a single crafted MPLS packet.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 4.2 (including) 4.3 (excluding)