The slhc_init function in drivers/net/slip/slhc.c in the Linux kernel through 4.2.3 does not ensure that certain slot numbers are valid, which allows local users to cause a denial of service (NULL pointer dereference and system crash) via a crafted PPPIOCSMAXCID ioctl call. <a href"http://cwe.mitre.org/data/definitions/476.html">CWE-476: NULL Pointer Dereference</a>
Publication date: Mon, 19 Oct 2015 15:59:00 +0000