Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 1428684 - RFE: Backport of ICMP ratelimit fixes.
RFE: Backport of ICMP ratelimit fixes.
Status: CLOSED ERRATA
Product: Red Hat Enterprise Linux 7
Classification: Red Hat
Component: kernel (Show other bugs)
7.4
Unspecified Unspecified
medium Severity medium
: rc
: ---
Assigned To: Sabrina Dubroca
Jianlin Shi
: FutureFeature
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2017-03-03 01:51 EST by Wade Mealing
Modified: 2017-08-02 01:47 EDT (History)
10 users (show)

See Also:
Fixed In Version: kernel-3.10.0-647.el7
Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2017-08-02 01:47:36 EDT
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2017:1842 normal SHIPPED_LIVE Important: kernel security, bug fix, and enhancement update 2017-08-01 14:22:09 EDT

  None (edit)
Description Wade Mealing 2017-03-03 01:51:49 EST
Description of problem:

As per discussion with Jesper Dangaard Brouer, he suggests that we need to backport specific fixes to reduce the icmp_send() ratelimit, which in turn has an affect on CVE-2017-5972 ( https://bugzilla.redhat.com/show_bug.cgi?id=1422081 ).

Version-Release number of selected component (if applicable):

Current RHEL 7.

Required backports:

 https://git.kernel.org/davem/net-next/c/9f2f27a9a518c
 https://git.kernel.org/davem/net-next/c/7ba91ecb16824
 https://git.kernel.org/davem/net-next/c/c0303efeab739
 https://git.kernel.org/davem/net-next/c/8d9ba388f35b3

I have not tested these, this is not considered a security flaw but a reccomended hardening fix.

Thanks,

Wade Mealing
Red Hat Product Security.
Comment 4 Rafael Aquini 2017-04-10 12:50:41 EDT
Patch(es) committed on kernel repository and an interim kernel build is undergoing testing
Comment 6 Rafael Aquini 2017-04-11 11:07:41 EDT
Patch(es) available on kernel-3.10.0-647.el7
Comment 8 Jianlin Shi 2017-05-11 02:31:45 EDT
related test passed:

https://beaker.engineering.redhat.com/jobs/1851885
Comment 9 Florian Weimer 2017-06-14 02:32:47 EDT
This changes introduces a regression, see bug 1461282.
Comment 11 errata-xmlrpc 2017-08-02 01:47:36 EDT
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHSA-2017:1842

Note You need to log in before you can comment on or make changes to this bug.