Back

HIGH

iptables: --syn flag bypass

Published Feb 15, 2014

Description

extensions/libxt_tcp.c in iptables through 1.4.21 does not match TCP SYN+FIN packets in --syn rules, which might allow remote attackers to bypass intended firewall restrictions via crafted packets. NOTE: the CVE-2012-6638 fix makes this issue less relevant.

Affected products

Remediation

Red Hat statement

This issue does affect Red Hat Enterprise Linux 5 and 6. The risks in breaking compatability associated with fixing this flaw outweigh the benefits of the fix, therefore Red Hat does not plan to fix this flaw in Red Hat Enterprise Linux 5 and 6. Please note that the remote DoS issue in the way how Linux kernel treats SYN+FIN flags set is being handled under different CVE, CVE-2012-6638, and is planned to be fixed in all affected Red Hat Enterprise Linux releases.

Red Hat mitigation

Instead of --syn use --tcp-flags SYN,RST,ACK SYN in your rulesets in case you want to also match packets with both SYN+FIN flags set.

Metrics

Weaknesses (0)

No CWE recorded.

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Feb 15, 2014
Updated Aug 6, 2024
Reserved May 14, 2012
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Moderate
Public date Dec 2, 2011