CVE-2012-2372

Published: 18 June 2012

The rds_ib_xmit function in net/rds/ib_send.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel 3.7.4 and earlier allows local users to cause a denial of service (BUG_ON and kernel panic) by establishing an RDS connection with the source IP address equal to the IPoIB interface's own IP address, as demonstrated by rds-ping.

From the Ubuntu security team

A flaw was found in the Linux kernel's Reliable Datagram Sockets (RDS) protocol implementation. A local, unprivileged user could use this flaw to cause a denial of service.

Priority

Low

Status

Package Release Status
linux
Launchpad, Ubuntu, Debian
Upstream
Released (3.13~rc4)
Patches:
Introduced by 639b321b4d8f4e412bfbb2a4a19bfebc1e68ace4
Fixed by 18fc25c94eadc52a42c025125af24657a93638c0
linux-armadaxp
Launchpad, Ubuntu, Debian
Upstream
Released (3.13~rc4)
linux-aws
Launchpad, Ubuntu, Debian
Upstream
Released (3.13~rc4)
linux-ec2
Launchpad, Ubuntu, Debian
Upstream
Released (3.13~rc4)
linux-flo
Launchpad, Ubuntu, Debian
Upstream
Released (3.13~rc4)
linux-fsl-imx51
Launchpad, Ubuntu, Debian
Upstream
Released (3.13~rc4)
linux-gke
Launchpad, Ubuntu, Debian
Upstream
Released (3.13~rc4)
linux-goldfish
Launchpad, Ubuntu, Debian
Upstream
Released (3.13~rc4)
linux-grouper
Launchpad, Ubuntu, Debian
Upstream
Released (3.13~rc4)
linux-hwe
Launchpad, Ubuntu, Debian
Upstream
Released (3.13~rc4)
linux-hwe-edge
Launchpad, Ubuntu, Debian
Upstream
Released (3.13~rc4)
linux-linaro-omap
Launchpad, Ubuntu, Debian
Upstream
Released (3.13~rc4)
linux-linaro-shared
Launchpad, Ubuntu, Debian
Upstream
Released (3.13~rc4)
linux-linaro-vexpress
Launchpad, Ubuntu, Debian
Upstream
Released (3.13~rc4)
linux-lts-backport-maverick
Launchpad, Ubuntu, Debian
Upstream
Released (3.13~rc4)
linux-lts-backport-natty
Launchpad, Ubuntu, Debian
Upstream
Released (3.13~rc4)
linux-lts-backport-oneiric
Launchpad, Ubuntu, Debian
Upstream
Released (3.13~rc4)
linux-lts-quantal
Launchpad, Ubuntu, Debian
Upstream
Released (3.13~rc4)
linux-lts-raring
Launchpad, Ubuntu, Debian
Upstream
Released (3.13~rc4)
linux-lts-saucy
Launchpad, Ubuntu, Debian
Upstream
Released (3.13~rc4)
linux-lts-trusty
Launchpad, Ubuntu, Debian
Upstream
Released (3.13~rc4)
linux-lts-utopic
Launchpad, Ubuntu, Debian
Upstream
Released (3.13~rc4)
linux-lts-vivid
Launchpad, Ubuntu, Debian
Upstream
Released (3.13~rc4)
linux-lts-wily
Launchpad, Ubuntu, Debian
Upstream
Released (3.13~rc4)
linux-lts-xenial
Launchpad, Ubuntu, Debian
Upstream
Released (3.13~rc4)
linux-maguro
Launchpad, Ubuntu, Debian
Upstream
Released (3.13~rc4)
linux-mako
Launchpad, Ubuntu, Debian
Upstream
Released (3.13~rc4)
linux-manta
Launchpad, Ubuntu, Debian
Upstream
Released (3.13~rc4)
linux-mvl-dove
Launchpad, Ubuntu, Debian
Upstream
Released (3.13~rc4)
linux-qcm-msm
Launchpad, Ubuntu, Debian
Upstream
Released (3.13~rc4)
linux-raspi2
Launchpad, Ubuntu, Debian
Upstream
Released (3.13~rc4)
linux-snapdragon
Launchpad, Ubuntu, Debian
Upstream
Released (3.13~rc4)
linux-ti-omap4
Launchpad, Ubuntu, Debian
Upstream
Released (3.13~rc4)

Notes

AuthorNote
jdstrand
linux-armadaxp is maintained by OEM
apw
this is claimed fixed by RedHat but I cannot find the fix anywhere, the
only reference I did find to the CVE in Fedora implies they have miss
tagged the fix for CVE-2012-2373 as 2372:
http://permalink.gmane.org/gmane.linux.redhat.fedora.extras.cvs/775892
note the patch is the x86 pmd patch.
needs-triage back to -security for lack of a clear direction on a fix (per
irc discussions)
Looking at the RHEL kernels it appears that this is the fix, though it
is not upstream as yet:
http://people.canonical.com/~apw/misc/cves/CVE-2012-2372-1.diff
kees
https://oss.oracle.com/git/?p=redpatch.git;a=commitdiff;h=c7b6a0a1d8d636852be130fa15fa8be10d4704e8
seems fixed upstream by 18fc25c94eadc52a42c025125af24657a93638c0

References

Bugs