DescriptionEugene Teo (Security Response)
2010-11-09 05:57:03 UTC
Description of problem:
INET-DIAG is inconsistent about how it looks up the bytecode contained in a
netlink message, making it possible for a user to cause the kernel to execute
unaudited INET-DIAG bytecode. This can be abused to make the kernel enter an infinite loop, and possibly other consequences.
Reference:
http://www.spinics.net/lists/netdev/msg145899.html
Acknowledgements:
Red Hat would like to thank Nelson Elhage for reporting this issue.
Comment 3Eugene Teo (Security Response)
2010-11-22 06:06:33 UTC
Statement:
This issue did not affect the version of Linux kernel as shipped with Red Hat Enterprise Linux 4 as it did not include support for monitoring of INET transport protocol sockets. Future updates in Red Hat Enterprise Linux 5, 6 and Red Hat Enterprise MRG may address this flaw.
Comment 4Eugene Teo (Security Response)
2010-11-22 13:24:13 UTC