Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2007-2172

15
FAUCET Score

CVE-2007-2172 is a low-severity vulnerability in the Linux kernel (versions 2.6 before 2.6.21-rc6 and 2.4 before 2.4.35) affecting Debian and Ubuntu distributions. It stems from a typo causing an out-of-bounds array access in network-related functions, specifically dn_fib_props and fib_props. The vulnerability has a CVSS score of 4.7, indicating a local attack vector with medium complexity, and its primary impact is a denial of service. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.4.0, < 2.4.35CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 2.6.0, <= 2.6.20CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
2.6.21CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:2.6.21:git1:*:*:*:*:*:*
2.6.21CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:2.6.21:git2:*:*:*:*:*:*
2.6.21CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:2.6.21:git3:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

4.7MEDIUM

AV:L/AC:M/Au:N/C:N/I:N/A:C

Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
COMPLETE
Access Vector
LOCAL
Access Complexity
MEDIUM
Authentication
NONE
Exploitability Score
3.4
Impact Score
6.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
0.43%
Probability of exploitation in next 30 days
EPSS Percentile
35.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0043 is in the 68th percentile among its peer group of 1,595 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (5)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 2.1Fixed in: kernel-0:2.4.18-e.67
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 2.1Fixed in: kernel-0:2.4.9-e.74
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 3Fixed in: kernel-0:2.4.21-53.EL
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: kernel-0:2.6.9-55.0.2.EL
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: kernel-0:2.6.18-8.1.4.el5
View patch

Vendor Advisories (1)

redhatCVE-2007-2172Important

fib_semantics.c out of bounds access vulnerability

Mar 26, 2007

References

kernel.org / pub/linux/kernel/v2.6/testing/ChangeLog-2.6.21-rc6
Vendor Advisory
rhn.redhat.com / errata/RHSA-2007-0488.html
Third Party Advisory
secunia.com / advisories/25068
Third Party Advisory
secunia.com / advisories/25288
Third Party Advisory
secunia.com / advisories/25392
Third Party Advisory
secunia.com / advisories/25838
Third Party Advisory
secunia.com / advisories/26289
Third Party Advisory
secunia.com / advisories/26450
Third Party Advisory
secunia.com / advisories/26620
Third Party Advisory
secunia.com / advisories/26647
Third Party Advisory
secunia.com / advisories/27913
Third Party Advisory
secunia.com / advisories/29058
Third Party Advisory
secunia.com / advisories/33280
Third Party Advisory
exchange.xforce.ibmcloud.com / vulnerabilities/33979
Third Party AdvisoryVDB Entry
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10764
Third Party Advisory
support.avaya.com / elmodocs2/security/ASA-2007-287.htm
Third Party Advisory
debian.org / security/2007/dsa-1356
Third Party Advisory
debian.org / security/2007/dsa-1363
Third Party Advisory
debian.org / security/2008/dsa-1503
Third Party Advisory
debian.org / security/2008/dsa-1504
Third Party Advisory
kernel.org / pub/linux/kernel/v2.4/ChangeLog-2.4.35
Vendor Advisory
mail-archive.com / git-commits-head%40vger.kernel.org/msg08269.html
mail-archive.com / git-commits-head%40vger.kernel.org/msg08270.html
mandriva.com / security/advisories
Third Party Advisory
mandriva.com / security/advisories
Third Party Advisory
mandriva.com / security/advisories
Third Party Advisory
redhat.com / support/errata/RHSA-2007-0347.html
Third Party Advisory
redhat.com / support/errata/RHSA-2007-1049.html
Third Party Advisory
redhat.com / support/errata/RHSA-2008-0787.html
Third Party Advisory
securityfocus.com / bid/23447
PatchThird Party AdvisoryVDB EntryVendor Advisory
ubuntu.com / usn/usn-464-1
Third Party Advisory
vupen.com / english/advisories/2007/2690
Third Party Advisory