CVE-2020-10711 Kernel: NetLabel: null pointer dereference while receiving CIPSO packet with null category

Related Vulnerabilities: CVE-2020-10711  
                							

                <!--X-Body-Begin-->
<!--X-User-Header-->

oss-sec
mailing list archives
<!--X-User-Header-End-->
<!--X-TopPNI-->

By Date

By Thread

</form>

<!--X-TopPNI-End-->
<!--X-MsgBody-->
<!--X-Subject-Header-Begin-->
CVE-2020-10711 Kernel: NetLabel: null pointer dereference while receiving CIPSO packet with null category

<!--X-Subject-Header-End-->
<!--X-Head-of-Message-->

From: P J P &lt;ppandit () redhat com&gt;

Date: Tue, 12 May 2020 17:46:44 +0530 (IST)

<!--X-Head-of-Message-End-->
<!--X-Head-Body-Sep-Begin-->

<!--X-Head-Body-Sep-End-->
<!--X-Body-of-Message-->
  Hello,

NULL pointer dereference(s) issue(s) was found in the Linux kernel's SELinux 
subsystem. It occurs while importing the Commercial IP Security Option (CIPSO) 
protocol's category bitmap into SELinux's extensible bitmap via 
'ebitmap_netlbl_import' routine. While parsing the CIPSO restricted bitmap tag 
in 'cipso_v4_parsetag_rbm' routine, it sets the security attribute to indicate 
that category bitmap is present, even if it has not been allocated. This leads 
to the said NULL pointer dereference issue while importing the same category 
bitmap into SELinux. A remote network user could use this flaw to crash the 
system kernel resulting in DoS scenario.

This issue was introduced by upstream commit:
  -&gt; https://git.kernel.org/linus/4b8feff251da3d7058b5779e21b33a85c686b974
     netlabel: fix the horribly broken catmap functions

* This issue was reported by Matthew Sheets (CC'd).
* Please see a proposed fix patch attached herein.

Thank you.
--
Prasad J Pandit / Red Hat Product Security Team
8685 545E B54C 486B C6EB 271E E285 8B5A F050 DE8DAttachment:
linux-netlabel-cope-with-null-catmap.patch
Description: 

<!--X-Body-of-Message-End-->
<!--X-MsgBody-End-->
<!--X-Follow-Ups-->

<!--X-Follow-Ups-End-->
<!--X-References-->
<!--X-References-End-->
<!--X-BotPNI-->

By Date

By Thread

Current thread:

CVE-2020-10711 Kernel: NetLabel: null pointer dereference while receiving CIPSO packet with null category P J P (May 12)

Re: CVE-2020-10711 Kernel: NetLabel: null pointer dereference while receiving CIPSO packet with null category P J P (May 12)

<!--X-BotPNI-End-->
<!--X-User-Footer-->
<!--X-User-Footer-End-->