The ip_frag_reasm function in net/ipv4/ip_fragment.c in the Linux kernel
2.6.32-rc8, and 2.6.29 and later versions before 2.6.32, calls
IP_INC_STATS_BH with an incorrect argument, which allows remote attackers
to cause a denial of service (NULL pointer dereference and hang) via long
IP packets, possibly related to the ip_defrag function.
Updated: 2016-03-23 03:33:52 UTC (commit 10817)