Array Index Overflow in xfrm_sk_policy_insert Function in Linux Kernel 2.6

Array Index Overflow in xfrm_sk_policy_insert Function in Linux Kernel 2.6

CVE-2005-2456 · MEDIUM Severity

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Array index overflow in the xfrm_sk_policy_insert function in xfrm_user.c in Linux kernel 2.6 allows local users to cause a denial of service (oops or deadlock) and possibly execute arbitrary code via a p->dir value that is larger than XFRM_POLICY_OUT, which is used as an index in the sock->sk_policy array.

Learn more about our Cis Benchmark Audit For Distribution Independent Linux.