CVE-2007-1734

Publication date 28 March 2007

Last updated 24 July 2024


Ubuntu priority

The DCCP support in the do_dccp_getsockopt function in net/dccp/proto.c in Linux kernel 2.6.20 and later does not verify the upper bounds of the optlen value, which allows local users running on certain architectures to read kernel memory or cause a denial of service (oops), a related issue to CVE-2007-1730.

Status

Package Ubuntu Release Status
linux-source-2.6.15 6.06 LTS dapper
Not affected
linux-source-2.6.17 6.10 edgy
Not affected
linux-source-2.6.20 7.04 feisty
Fixed 2.6.20-16.28