MNBSD-2019-4: Missing contiguity check in m_pulldown(9) allows remote IPv6 denial of service

Severity: Unknown

Affected Package: kernel

Summary: Missing contiguity check in m_pulldown(9) allows remote IPv6 denial of service

Description

Due to a missing check in the code of m_pulldown(9), data returned may not be contiguous as requested by the caller. When processing IPv6 fragments a remote attacker can send specially crafted traffic that triggers a kernel error condition and panic, resulting in a remote denial of service.

Affected Versions

kernel

Recommendations

No specific recommendations provided.

References

Additional Information

Aliases: CVE-2019-5611

Published: August 21, 2019
Last Modified: August 21, 2019