Linux IGMP DoS

Strike ID:
D12-oj901
CVSS:
7.8 (AV:N/AC:L/Au:N/C:N/I:N/A:C)
False Positive:
f
Variants:
1
Year:
2012

Description

This strike sends an IGMPv2 general membership query, if the mdb database has not been created in Linux, but the box is set up as a bridge, which is the default setup in many cases, the membership query will trigger a kernel panic caused by a null pointer dereference. This bug introduced at some point before 2.6.35-rc4, it is not an exploit, and to an IPS/IDS this should look like normal multicast traffic.

CVE

References

Bid