First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 154327
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Sune Kloppenborg Jeppesen <jaervosz@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 154327 depends on: Show dependency tree
Bug 154327 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2006-11-07 00:50 0000
[NETFILTER]: Fix ip6_tables extension header bypass bug

As reported by Mark Dowd <Mark_Dowd@McAfee.com>, ip6_tables is susceptible
to a fragmentation attack causing false negatives on extension header matches.

When extension headers occur in the non-first fragment after the fragment
header (possibly with an incorrect nexthdr value in the fragment header)
a rule looking for this extension header will never match.

Drop fragments that are at offset 0 and don't contain the final protocol
header regardless of the ruleset, since this should not happen normally.
Since all extension headers are before the protocol header this makes sure
an extension header is either not present or in the first fragment, where
we can properly parse it.

With help from Yasuyuki KOZAKAI <yasuyuki.kozakai@toshiba.co.jp>.

Signed-off-by: Patrick McHardy <kaber@trash.net>
Signed-off-by: David S. Miller <davem@davemloft.net>

------- Comment #1 From Harlan Lieberman-Berg (RETIRED) 2006-12-21 19:18:59 0000 -------
hppa-sources: Gmsoft, bump to 2.6.19 or patch please.
mips-sources: Kumba, bump to 2.6.19 or patch please.
rsbac-sources: Kang, bump to 2.6.19 or patch please.
systrace-sources: Lcars, bump to 2.6.19 or patch please.
usermode-sources: Dang, bump to 2.6.19 or patch please.
xen-sources: Someone.... bump to 2.6.19 or patch please.

------- Comment #2 From Guy Martin 2006-12-23 03:51:25 0000 -------
hppa-sources-2.6.19.1 commited.

------- Comment #3 From Daniel Gryniewicz 2007-01-02 20:32:26 0000 -------
usermode-sources-2.6.18-r1 is added.

------- Comment #4 From Guillaume Destuynder (RETIRED) 2007-01-12 13:41:00 0000 -------
rsbac-sources-2.6.19 is in cvs (~arch)

------- Comment #5 From Andrew Ross (RETIRED) 2007-01-27 06:03:07 0000 -------
Thanks, this is fixed in xen-sources-2.6.16.28-r2, which will hit the tree in a
few hours (just waiting for the mirrors to update before I commit the ebuild).

------- Comment #6 From Harlan Lieberman-Berg (RETIRED) 2007-05-21 23:20:01 0000 -------
.

First Last Prev Next    No search results available      Search page      Enter new bug