oss-sec mailing list archives
Re: CVE-2016-7039 Kernel: net: unbounded recursion in the vlan GRO processing
From: P J P <ppandit () redhat com>
Date: Tue, 11 Oct 2016 22:47:00 +0530 (IST)
+-- On Mon, 10 Oct 2016, P J P wrote --+ | Linux kernel built with the 802.1Q/802.1ad VLAN(CONFIG_VLAN_8021Q) OR Virtual | eXtensible Local Area Network(CONFIG_VXLAN) with Transparent Ethernet | Bridging(TEB) GRO support, is vulnerable to a stack overflow issue. It could | occur while receiving large packets via GRO path; As an unlimited recursion | could unfold in both VLAN and TEB modules, leading to a stack corruption in | the kernel. Upstream patch: (under review) --------------- -> https://patchwork.ozlabs.org/patch/680412/ Thank you. -- Prasad J Pandit / Red Hat Product Security Team 47AF CE69 3A90 54AA 9045 1053 DD13 3D32 FE5B 041F
Current thread:
- CVE-2016-7039 Kernel: net: unbounded recursion in the vlan GRO processing P J P (Oct 10)
- Re: CVE-2016-7039 Kernel: net: unbounded recursion in the vlan GRO processing P J P (Oct 11)