Bug 865492 (CVE-2012-4517)

Summary: CVE-2012-4517 ibacm: DoS (ibacm deamon crash) by joining responses for multicast destinations
Product: [Other] Security Response Reporter: Jan Lieskovsky <jlieskov>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: dledford, honli, jrusnack
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
: 866222 (view as bug list) Environment:
Last Closed: 2015-08-22 14:54:33 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 866222    
Bug Blocks: 855229, 865513    

Description Jan Lieskovsky 2012-10-11 15:02:50 UTC
A denial of service flaw was found in the way ibacm, an InfiniBand communication manager assistant, performed management of reference counts for multicast connections. The default reference count value for multicast connection is set to zero and when the multicast connection got released, an attempt was made to free it, possibly resulting in ib_acm service / daemon crash.

Upstream patch:
[1] http://git.openfabrics.org/git?p=~shefty/ibacm.git;a=commit;h=c7d28b35d64333c262de3ec972c426423dadccf9

Comment 1 Jan Lieskovsky 2012-10-11 15:04:19 UTC
This issue affects the version of the ibacm package, as shipped with Red Hat Enterprise Linux 6.

Comment 2 Jan Lieskovsky 2012-10-11 15:51:57 UTC
CVE Request:
[2] http://www.openwall.com/lists/oss-security/2012/10/11/6

Comment 3 Vincent Danen 2012-10-11 21:17:28 UTC
This was assigned CVE-2012-4517.

Comment 6 errata-xmlrpc 2013-02-21 09:48:44 UTC
This issue has been addressed in following products:

  Red Hat Enterprise Linux 6

Via RHSA-2013:0509 https://rhn.redhat.com/errata/RHSA-2013-0509.html

Comment 7 Huzaifa S. Sidhpurwala 2013-02-22 04:46:51 UTC
Statement:

(none)