Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 678904 (CVE-2019-9162) - Kernel: out-of-bounds read/write in et/ipv4/netfilter/nf_nat_snmp_basic_main.c in the SNMP NAT module (CVE-2019-9162)
Summary: Kernel: out-of-bounds read/write in et/ipv4/netfilter/nf_nat_snmp_basic_main....
Status: RESOLVED FIXED
Alias: CVE-2019-9162
Product: Gentoo Security
Classification: Unclassified
Component: Kernel (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Kernel Security
URL: https://bugzilla.redhat.com/show_bug....
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2019-02-27 08:32 UTC by Agostino Sarubbo
Modified: 2022-03-26 00:58 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2019-02-27 08:32:00 UTC
From ${URL} :

In the Linux kernel before 4.20.12, net/ipv4/netfilter/nf_nat_snmp_basic_main.c in the SNMP NAT module has insufficient ASN.1 length checks 
(aka an array index error), making out-of-bounds read and write operations possible, leading to an OOPS or local privilege escalation. This 
affects snmp_version and snmp_helper.

Upstream commit:
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=c4c07b4d6fa1f11880eab8e076d3d060ef3f55fc
https://github.com/torvalds/linux/commit/c4c07b4d6fa1f11880eab8e076d3d060ef3f55fc

Reference:
https://bugs.chromium.org/p/project-zero/issues/detail?id=1776
Comment 1 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-03-26 00:58:17 UTC
Fix in 4.19.25, 4.20.12, 5.0.