<!--X-Body-Begin-->
<!--X-User-Header-->
oss-sec
mailing list archives
<!--X-User-Header-End-->
<!--X-TopPNI-->
By Date
By Thread
</form>
<!--X-TopPNI-End-->
<!--X-MsgBody-->
<!--X-Subject-Header-Begin-->
CVE-2021-20177 kernel: iptables string match rule could result in kernel panic
<!--X-Subject-Header-End-->
<!--X-Head-of-Message-->
From: Wade Mealing <wmealing () redhat com>
Date: Tue, 12 Jan 2021 16:58:07 +1000
<!--X-Head-of-Message-End-->
<!--X-Head-Body-Sep-Begin-->
<!--X-Head-Body-Sep-End-->
<!--X-Body-of-Message-->
Gday,
A flaw was found in the Linux kernels implementation of string matching
within a packet. A privileged user
(with root or CAP_NET_ADMIN ) when inserting iptables rules could insert a
rule which can panic the system.
Likely a user with these permissions could do worse, however it crashes the
system (DOS) and the user is going to have a bad day
especially if the rule is inserted and restored on every boot.
At this time it doesn't affect RHEL releases, and there are fixes already
in multiple upstream trees.
Thanks,
Wade Mealing
Upstream patch:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=ca58fbe06c54
Upstream bugzilla:
https://bugzilla.kernel.org/show_bug.cgi?id=209823
Red Hat Bugzilla:
https://bugzilla.redhat.com/show_bug.cgi?id=1914719
--
Wade Mealing
Product Security - Kernel, RHCE
Red Hat
<https://www.redhat.com>
wmealing () redhat com
<https://red.ht/sig>
TRIED. TESTED. TRUSTED. <https://redhat.com/trusted>
secalert () redhat com for urgent response
<!--X-Body-of-Message-End-->
<!--X-MsgBody-End-->
<!--X-Follow-Ups-->
<!--X-Follow-Ups-End-->
<!--X-References-->
<!--X-References-End-->
<!--X-BotPNI-->
By Date
By Thread
Current thread:
CVE-2021-20177 kernel: iptables string match rule could result in kernel panic Wade Mealing (Jan 11)
Re: CVE-2021-20177 kernel: iptables string match rule could result in kernel panic Greg KH (Jan 12)
Re: CVE-2021-20177 kernel: iptables string match rule could result in kernel panic John Haxby (Jan 12)
Re: CVE-2021-20177 kernel: iptables string match rule could result in kernel panic David A. Wheeler (Jan 12)
Re: CVE-2021-20177 kernel: iptables string match rule could result in kernel panic Sasha Levin (Jan 12)
Re: CVE-2021-20177 kernel: iptables string match rule could result in kernel panic Philip Pettersson (Jan 12)
Re: CVE-2021-20177 kernel: iptables string match rule could result in kernel panic Greg KH (Jan 12)
Re: CVE-2021-20177 kernel: iptables string match rule could result in kernel panic Solar Designer (Jan 12)
<!--X-BotPNI-End-->
<!--X-User-Footer-->
<!--X-User-Footer-End-->