kernel: denial of service (DoS) attack against IPv6 network stacks due to improper handling of Router Advertisements.
Published May 27, 2015
3.3
LOWCVSS 2.0
EPSS 3.01%
Description
The ndisc_router_discovery function in net/ipv6/ndisc.c in the Neighbor Discovery (ND) protocol implementation in the IPv6 stack in the Linux kernel before 3.19.6 allows remote attackers to reconfigure a hop-limit setting via a small hop_limit value in a Router Advertisement (RA) message.
Affected products
No data.
Configuration 1
- ≤ 3.19.5
Configuration 2
- 20
- 21
- 22
Configuration 4
- 2.5
Configuration 5
- 7.0
- 8.0
No data.
Red Hat Enterprise Linux 6
kernel-0:2.6.32-504.30.3.el6
Fixed · RHSA-2015:1221
Red Hat Enterprise Linux 7
kernel-0:3.10.0-229.11.1.ael7b
Fixed · RHSA-2015:1534
Red Hat Enterprise Linux 7
kernel-rt-0:3.10.0-229.11.1.rt56.141.11.el7_1
Fixed · RHSA-2015:1565
Red Hat Enterprise MRG 2
kernel-rt-1:3.10.0-229.rt56.158.el6rt
Fixed · RHSA-2015:1564
Red Hat Enterprise Linux 5
kernel
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel-0:2.6.32-504.30.3.el6 | Fixed | RHSA-2015:1221 |
| Red Hat Enterprise Linux 7 | kernel-0:3.10.0-229.11.1.ael7b | Fixed | RHSA-2015:1534 |
| Red Hat Enterprise Linux 7 | kernel-rt-0:3.10.0-229.11.1.rt56.141.11.el7_1 | Fixed | RHSA-2015:1565 |
| Red Hat Enterprise MRG 2 | kernel-rt-1:3.10.0-229.rt56.158.el6rt | Fixed | RHSA-2015:1564 |
| Red Hat Enterprise Linux 5 | kernel | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue affects the versions of the Linux kernel as shipped with Red Hat Enterprise Linux 5, 6, 7 and Red Hat Enterprise MRG 2. Future kernel updates for Red Hat Enterprise Linux 5, 6, 7 and Red Hat Enterprise MRG 2 may address this issue. Red Hat Enterprise Linux 5 is now in Production 3 phase of the support and maintenance life cycle. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.
References (22)
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=6fd99094de2b83d1d4c8457f2c83483b2828e75a x_refsource_CONFIRM
- http://lists.fedoraproject.org/pipermail/package-announce/2015-April/155804.html vendor-advisoryx_refsource_FEDORAThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2015-April/155854.html vendor-advisoryx_refsource_FEDORAThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2015-April/155908.html vendor-advisoryx_refsource_FEDORAThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00023.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00011.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00004.html vendor-advisoryx_refsource_SUSE
- http://rhn.redhat.com/errata/RHSA-2015-1221.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2015-1534.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2015-1564.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://www.debian.org/security/2015/dsa-3237 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.19.6 x_refsource_CONFIRMExploitVendor Advisory
- http://www.openwall.com/lists/oss-security/2015/04/04/2 mailing-listx_refsource_MLISTExploit
- http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.html x_refsource_CONFIRMThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html x_refsource_CONFIRMThird Party Advisory
- http://www.securityfocus.com/bid/74315 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id/1032417 vdb-entryx_refsource_SECTRACK
- https://access.redhat.com/security/cve/CVE-2015-2922 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1203712 x_refsource_CONFIRMIssue Tracking
- https://github.com/torvalds/linux/commit/6fd99094de2b83d1d4c8457f2c83483b2828e75a x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2015-2922
- https://www.cve.org/CVERecord?id=CVE-2015-2922
Change history (0)
No recorded changes yet.