CVE-2015-6496

Severity CVSS v4.0:
Pending analysis
Type:
CWE-17 Code Errors
Publication date:
24/08/2015
Last modified:
12/04/2025

Description

conntrackd in conntrack-tools 1.4.2 and earlier does not ensure that the optional kernel modules are loaded before using them, which allows remote attackers to cause a denial of service (crash) via a (1) DCCP, (2) SCTP, or (3) ICMPv6 packet.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:netfilter:conntrack-tools:*:*:*:*:*:*:*:* 1.4.2 (including)
cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*