Bug 459955 (CVE-2008-3792)

Summary: CVE-2008-3792 kernel: sctp: fix potential panics in the SCTP-AUTH API
Product: [Other] Security Response Reporter: Eugene Teo (Security Response) <eteo>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: bhu, lgoncalv, lwang, williams
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2010-12-21 17:22:01 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 459956    
Bug Blocks:    
Attachments:
Description Flags
Upstream patch for this issue
none
Proposed backported patch for MRG kernel (untested) none

Description Eugene Teo (Security Response) 2008-08-25 07:29:16 UTC
Description of problem:
All of the SCTP-AUTH socket options could cause a panic if the extension is disabled and the API is envoked.

Additionally, there were some additional assumptions that certain pointers would always be valid which may not always be the case.

References:
http://marc.info/?l=linux-netdev&m=121928747903176&w=2
http://lkml.org/lkml/2008/8/23/49
http://www.openwall.com/lists/oss-security/2008/08/25/1

Comment 2 Eugene Teo (Security Response) 2008-08-25 07:31:48 UTC
Created attachment 314907 [details]
Upstream patch for this issue

Comment 3 Eugene Teo (Security Response) 2008-08-25 07:38:08 UTC
SCTP-AUTH API was introduced in upstream commit 65b07e5d (20070916).

Comment 5 Eugene Teo (Security Response) 2008-08-29 08:20:11 UTC
Created attachment 315342 [details]
Proposed backported patch for MRG kernel (untested)

Comment 6 Luis Claudio R. Goncalves 2008-09-05 12:16:56 UTC
Queued for -79

Comment 7 Vincent Danen 2010-12-21 17:22:01 UTC
This was addressed via:

MRG Realtime for RHEL 5 Server (RHSA-2008:0857)