keep skb->dst around in presence of IP options in kernel-ipv4 CVE-2017-5970 remote

Tracked by Jolla

asked 2017-07-06 15:47:51 +0300

this post is marked as community wiki

This post is a wiki. Anyone with karma >75 is welcome to improve it.

updated 2017-07-06 15:47:51 +0300

lpr gravatar image

Description
The ipv4_pktinfo_prepare function in net/ipv4/ip_sockglue.c in the Linux kernel through 4.9.9 allows attackers to cause a denial of service (system crash) via (1) an application that makes crafted system calls or possibly (2) IPv4 traffic with invalid IP options. 7.5high (attack range: remote)

Patch available upstream.

file affected: kernel-adaptation-sbj-3.4.108.20161101.1/net/ipv4/ip_sockglue.c lines 1040-1046

edit retag flag offensive close delete

Comments

Please, give me your email.

Daeto ( 2017-07-07 00:47:45 +0300 )edit

@Daeto why?

lpr ( 2017-07-08 15:15:02 +0300 )edit