Bug 865492 (CVE-2012-4517)

Summary: CVE-2012-4517 ibacm: DoS (ibacm deamon crash) by joining responses for multicast destinations
Product: [Other] Security Response Reporter: Jan Lieskovsky <jlieskov>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: dledford, honli, jrusnack
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard: impact=low,public=20120404,reported=20121010,source=internet,cvss2=4.3/AV:N/AC:M/Au:N/C:N/I:N/A:P,rhel-6/ibacm=affected
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
: 866222 (view as bug list) Environment:
Last Closed: 2015-08-22 10:54:33 EDT Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Bug Depends On: 866222    
Bug Blocks: 855229, 865513    

Description Jan Lieskovsky 2012-10-11 11:02:50 EDT
A denial of service flaw was found in the way ibacm, an InfiniBand communication manager assistant, performed management of reference counts for multicast connections. The default reference count value for multicast connection is set to zero and when the multicast connection got released, an attempt was made to free it, possibly resulting in ib_acm service / daemon crash.

Upstream patch:
[1] http://git.openfabrics.org/git?p=~shefty/ibacm.git;a=commit;h=c7d28b35d64333c262de3ec972c426423dadccf9
Comment 1 Jan Lieskovsky 2012-10-11 11:04:19 EDT
This issue affects the version of the ibacm package, as shipped with Red Hat Enterprise Linux 6.
Comment 2 Jan Lieskovsky 2012-10-11 11:51:57 EDT
CVE Request:
[2] http://www.openwall.com/lists/oss-security/2012/10/11/6
Comment 3 Vincent Danen 2012-10-11 17:17:28 EDT
This was assigned CVE-2012-4517.
Comment 6 errata-xmlrpc 2013-02-21 04:48:44 EST
This issue has been addressed in following products:

  Red Hat Enterprise Linux 6

Via RHSA-2013:0509 https://rhn.redhat.com/errata/RHSA-2013-0509.html
Comment 7 Huzaifa S. Sidhpurwala 2013-02-21 23:46:51 EST
Statement:

(none)