CVE-2005-3858
Last modified
CVE-2005-3858 is a vulnerability of currently unknown severity. Memory leak in the ip6_input_finish function in ip6_input.c in Linux kernel 2.6.12 and earlier might allow attackers to cause a denial of service via malformed IPv6 packets with unspecified parameter problems, which prevents the SKB from being freed.. EPSS estimates a 3.29% chance of exploitation in the next 30 days.
Description
Memory leak in the ip6_input_finish function in ip6_input.c in Linux kernel 2.6.12 and earlier might allow attackers to cause a denial of service via malformed IPv6 packets with unspecified parameter problems, which prevents the SKB from being freed.
Metrics
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Linux | Linux Kernel | 2.6.0 | — |
| Linux | Linux Kernel | 2.6.1 | — |
| Linux | Linux Kernel | 2.6.2 | — |
| Linux | Linux Kernel | 2.6.3 | — |
| Linux | Linux Kernel | 2.6.4 | — |
| Linux | Linux Kernel | 2.6.5 | — |
| Linux | Linux Kernel | 2.6.6 | — |
| Linux | Linux Kernel | 2.6.7 | — |
| Linux | Linux Kernel | 2.6.8 | — |
| Linux | Linux Kernel | 2.6.8.1 | — |
| Linux | Linux Kernel | 2.6.9 | 2.6.20 |
| Linux | Linux Kernel | 2.6.10 | — |
| Linux | Linux Kernel | 2.6.11 | — |
| Linux | Linux Kernel | 2.6.11.1 | — |
| Linux | Linux Kernel | 2.6.11.2 | — |
| Linux | Linux Kernel | 2.6.11.3 | — |
| Linux | Linux Kernel | 2.6.11.4 | — |
| Linux | Linux Kernel | 2.6.11.5 | — |
| Linux | Linux Kernel | 2.6.11.6 | — |
| Linux | Linux Kernel | 2.6.11.7 | — |
| Linux | Linux Kernel | 2.6.11.8 | — |
| Linux | Linux Kernel | 2.6.11.9 | — |
| Linux | Linux Kernel | 2.6.11.10 | — |
| Linux | Linux Kernel | 2.6.11.11 | — |
| Linux | Linux Kernel | 2.6.11.12 | — |
| Linux | Linux Kernel | 2.6.12 | — |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2005-3858?
How severe is CVE-2005-3858?
How do I fix CVE-2005-3858?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2005
- CVE-2005-3852SQL injection vulnerability in search.asp in Online Work Ord…
- CVE-2005-3853SQL injection vulnerability in snews.php in sNews 1.3 and ea…
- CVE-2005-3854Cross-site scripting (XSS) vulnerability in index.php in Eas…
- CVE-2005-3855SQL injection vulnerability in process.php in 1-2-3 music st…
- CVE-2005-3856The Popular URL capability (popularurls.cpp) in Krusader 1.6…
- CVE-2005-3857The time_out_leases function in locks.c for Linux kernel bef…
- CVE-2005-3859PHP remote file inclusion vulnerability in q-news.php in Q-N…
- CVE-2005-3860PHP remote file inclusion vulnerability in athena.php in Oli…
- CVE-2005-3861PHP remote file inclusion vulnerability in content.php in ph…
- CVE-2005-3862Buffer overflow in unalz before 0.53 allows remote attackers…
- CVE-2005-3863Stack-based buffer overflow in kkstrtext.h in ktools library…
- CVE-2005-3864SQL injection vulnerability in index.php in SourceWell 1.1.2…
Are you affected by CVE-2005-3858?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
