This service will be undergoing maintenance at 00:00 UTC, 2016-08-01. It is expected to last about 1 hours

Bug 865492 (CVE-2012-4517)

Summary: CVE-2012-4517 ibacm: DoS (ibacm deamon crash) by joining responses for multicast destinations
Product: [Other] Security Response Reporter: Jan Lieskovsky <jlieskov>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: dledford, honli, jrusnack
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard: impact=low,public=20120404,reported=20121010,source=internet,cvss2=4.3/AV:N/AC:M/Au:N/C:N/I:N/A:P,rhel-6/ibacm=affected
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
: 866222 (view as bug list) Environment:
Last Closed: 2015-08-22 10:54:33 EDT Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Bug Depends On: 866222    
Bug Blocks: 855229, 865513    

Description Jan Lieskovsky 2012-10-11 11:02:50 EDT
A denial of service flaw was found in the way ibacm, an InfiniBand communication manager assistant, performed management of reference counts for multicast connections. The default reference count value for multicast connection is set to zero and when the multicast connection got released, an attempt was made to free it, possibly resulting in ib_acm service / daemon crash.

Upstream patch:
Comment 1 Jan Lieskovsky 2012-10-11 11:04:19 EDT
This issue affects the version of the ibacm package, as shipped with Red Hat Enterprise Linux 6.
Comment 2 Jan Lieskovsky 2012-10-11 11:51:57 EDT
CVE Request:
Comment 3 Vincent Danen 2012-10-11 17:17:28 EDT
This was assigned CVE-2012-4517.
Comment 6 errata-xmlrpc 2013-02-21 04:48:44 EST
This issue has been addressed in following products:

  Red Hat Enterprise Linux 6

Via RHSA-2013:0509
Comment 7 Huzaifa S. Sidhpurwala 2013-02-21 23:46:51 EST