oss-sec mailing list archives
Re: CVE Request: Linux: net: out-of-bounds due do a signedness issue when defragging ipv6
From: <cve-assign () mitre org>
Date: Thu, 1 Dec 2016 14:15:46 -0500
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256
A fix was sent upstream: https://www.spinics.net/lists/netdev/msg407525.html More details here: https://groups.google.com/forum/#!topic/syzkaller/GFbGpX7nTEo
Problem is that all network headers before fragment header are pulled. Normal ipv6 reassembly will drop the skb when errors occur further down the line. netfilter doesn't do this
Use CVE-2016-9755. The scope of this CVE does not include the GFbGpX7nTEo discussion of https://groups.google.com/forum/#!original/syzkaller/GFbGpX7nTEo/XIKCs1NwAwAJ "A quick grep shows that the same issue can potentially happen in multiple places across the kernel" - -- CVE Assignment Team M/S M300, 202 Burlington Road, Bedford, MA 01730 USA [ A PGP key is available for encrypted communications at http://cve.mitre.org/cve/request_id.html ] -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCAAGBQJYQHVxAAoJEHb/MwWLVhi2ivwQAK972EbLLzsDaSmHZyK/hlEG 08kbLjW7Fmvs4GjSEb3XWMYI7IZzuZOURbCwyZQ9jcXDdAk371trf7OIX/aImXxM L6vFWqU2KZE+p/BkK9BbEJvkExUDPEO2mF10kHVrGBFvmM5u6zGPKynwaWWHZXwo j52JVuGvJUxvFOSUVJBKwxhjEgEx4TYnc5M7r0aO9mfAs9/ZbJZmJ33ZXHwS+UAu feIwdIZk2dEzY6CUg8vJ+IGxh5O6m/9KECend3yA47GQRprYqIWMkfqg2RUcPjsH BX78nJQmZWpahDbbst3PD+VUvLh617hOlipZnBLujoe3ts4dyFbv6QRvVfCMQy/8 ua1s0su0PpnJNFXuS+MydirJB2VhpLFka7fIjYrmwLdIMHWw90GW7rpTRvrUAW/A tKcTL9zPeU75M2VIT4/zonUXK9Gb5nDvdsvSQxWDe4fptlJe8OfmzXbf3KpSaHRd 8RxqX4VeHiHA/rQCxpMlnq1RK5IIth9YusbK52LBqf5q14WBQsUTIMkUlo0lJ1Qa x5Pr3AkVRcOlqCeMmg6IILPHdNfOgoEVYgtlDzh0OZNXk6T6PvK6c3GnMCo8JcFt HNuCdLMG4NMr7iX4W0Ptu31IwQC5bBmL7dn07OwJkVDJ5OLYe2QYUBKfofjMgEKg GvcQC04f5qGYKWPU14/C =YbPe -----END PGP SIGNATURE-----
Current thread:
- CVE Request: Linux: net: out-of-bounds due do a signedness issue when defragging ipv6 Andrey Konovalov (Dec 01)
- Re: CVE Request: Linux: net: out-of-bounds due do a signedness issue when defragging ipv6 cve-assign (Dec 01)