Red Hat Bugzilla – Bug 1428684
RFE: Backport of ICMP ratelimit fixes.
Last modified: 2017-08-02 01:47:36 EDT
Description of problem: As per discussion with Jesper Dangaard Brouer, he suggests that we need to backport specific fixes to reduce the icmp_send() ratelimit, which in turn has an affect on CVE-2017-5972 ( https://bugzilla.redhat.com/show_bug.cgi?id=1422081 ). Version-Release number of selected component (if applicable): Current RHEL 7. Required backports: https://git.kernel.org/davem/net-next/c/9f2f27a9a518c https://git.kernel.org/davem/net-next/c/7ba91ecb16824 https://git.kernel.org/davem/net-next/c/c0303efeab739 https://git.kernel.org/davem/net-next/c/8d9ba388f35b3 I have not tested these, this is not considered a security flaw but a reccomended hardening fix. Thanks, Wade Mealing Red Hat Product Security.
Patch(es) committed on kernel repository and an interim kernel build is undergoing testing
Patch(es) available on kernel-3.10.0-647.el7
related test passed: https://beaker.engineering.redhat.com/jobs/1851885
This changes introduces a regression, see bug 1461282.
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHSA-2017:1842