The ip_frag_reasm function in net/ipv4/ip_fragment.c in the Linux kernel
2.6.32-rc8, and 2.6.29 and later versions before 2.6.32, calls
IP_INC_STATS_BH with an incorrect argument, which allows remote attackers
to cause a denial of service (NULL pointer dereference and hang) via long
IP packets, possibly related to the ip_defrag function.
Updated: 2015-07-29 20:35:36 UTC (commit 9756)