Description
Integer underflow in the ieee80211_rx function in net/ieee80211/ieee80211_rx.c in the Linux kernel 2.6.x before 2.6.23 allows remote attackers to cause a denial of service (crash) via a crafted SKB length value in a runt IEEE 802.11 frame when the IEEE80211_STYPE_QOS_DATA flag is set, aka an "off-by-two error."
Published: 2007-11-06
Score: 7.1 High
EPSS: 5.4% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-1428-2 New Linux 2.6.18 packages fix several vulnerabilities
Debian DSA Debian DSA DSA-1481-1 New Linux 2.6.18 packages fix several vulnerabilities
EUVD EUVD EUVD-2007-4978 Integer underflow in the ieee80211_rx function in net/ieee80211/ieee80211_rx.c in the Linux kernel 2.6.x before 2.6.23 allows remote attackers to cause a denial of service (crash) via a crafted SKB length value in a runt IEEE 802.11 frame when the IEEE80211_STYPE_QOS_DATA flag is set, aka an "off-by-two error."
Ubuntu USN Ubuntu USN USN-558-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-574-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-578-1 Linux kernel vulnerabilities
References
Link Providers
ftp://ftp.kernel.org/pub/linux/kernel/people/bunk/linux-2.6.16.y/testing/ChangeLog-2.6.16.57-rc1 cve-icon cve-icon
http://git.kernel.org/?p=linux/kernel/git/avi/kvm.git%3Ba=commitdiff%3Bh=04045f98e0457aba7d4e6736f37eed189c48a5f7 cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2007-12/msg00001.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00002.html cve-icon cve-icon
http://secunia.com/advisories/27555 cve-icon cve-icon
http://secunia.com/advisories/27614 cve-icon cve-icon
http://secunia.com/advisories/27824 cve-icon cve-icon
http://secunia.com/advisories/27912 cve-icon cve-icon
http://secunia.com/advisories/28033 cve-icon cve-icon
http://secunia.com/advisories/28162 cve-icon cve-icon
http://secunia.com/advisories/28170 cve-icon cve-icon
http://secunia.com/advisories/28706 cve-icon cve-icon
http://secunia.com/advisories/28806 cve-icon cve-icon
http://secunia.com/advisories/28971 cve-icon cve-icon
http://www.debian.org/security/2007/dsa-1428 cve-icon cve-icon
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.23 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDKSA-2007:226 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDKSA-2007:232 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDVSA-2008:008 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDVSA-2008:105 cve-icon cve-icon
http://www.novell.com/linux/security/advisories/2007_59_kernel.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2007-0993.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2007-1104.html cve-icon cve-icon
http://www.securityfocus.com/bid/26337 cve-icon cve-icon
http://www.ubuntu.com/usn/usn-558-1 cve-icon cve-icon
http://www.ubuntu.com/usn/usn-574-1 cve-icon cve-icon
http://www.ubuntu.com/usn/usn-578-1 cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/3718 cve-icon cve-icon
https://exchange.xforce.ibmcloud.com/vulnerabilities/38247 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2007-4997 cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10596 cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2007-4997 cve-icon
History

No history.

Subscriptions

Linux Linux Kernel
Redhat Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-07T15:17:27.827Z

Reserved: 2007-09-20T00:00:00.000Z

Link: CVE-2007-4997

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2007-11-06T19:46:00.000

Modified: 2026-04-23T00:35:47.467

Link: CVE-2007-4997

cve-icon Redhat

Severity : Important

Publid Date: 2007-10-02T00:00:00Z

Links: CVE-2007-4997 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses