CVE-2005-3274 describes a race condition in the ip_vs_conn_flush function within the Linux kernel (versions 2.6 before 2.6.13 and 2.4 before 2.4.32-pre2) on Symmetric Multiprocessing (SMP) systems, affecting Debian and other Linux distributions. This vulnerability allows a local attacker to trigger a denial of service (null dereference) by causing a connection timer to expire during a connection table flush before a necessary lock is acquired. Rated Medium severity (CVSS 4.7), it requires local access and high attack complexity, leading to a high impact on availability. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.4.0, <= 2.4.31CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 2.6.0, < 2.6.13CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
3.1CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:3.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.