The IPv4 implementation in the Linux kernel before 3.18.8 does not properly consider the length of the Read-Copy Update (RCU) grace period for redirecting lookups in the absence of caching, which allows remote attackers to cause a denial of service (memory consumption or system crash) via a flood of packets.
CVSS Vector
AV:N/AC:L/Au:N/C:N/I:N/A:CCanonical Ubuntu
OSCanonical12.0414.0414.10Linux Kernel
OSLinux3.15.7 – 3.16.35 (excl.)3.10.50 – 3.10.70 (excl.)3.17 – 3.18.8 (excl.)3.12.26 – 3.12.38 (excl.)3.14.14 – 3.14.34 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
DoS
CWE
References
Related vulnerabilities
CVE-2025-10585CRITICAL9.8⚠ KEVPL ✓same product
Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty
CVE-2025-32463CRITICAL9.3⚠ KEVPL ✓same product
Sudo: eskalacja uprawnień do root poprzez opcję --chroot (CVE-2025-32463)
CVE-2025-34028CRITICAL9.3⚠ KEVPL ✓same product
Commvault Command Center – nieuwierzytelniony RCE przez path traversal w ZIP
CVE-2022-47986CRITICAL9.8⚠ KEVPL ✓same product
RCE przez YAML deserialization w IBM Aspera Faspex
CVE-2022-22954CRITICAL9.8⚠ KEVPL ✓same product
RCE w VMware Workspace ONE Access i Identity Manager poprzez server-side template injection