Bug 2211440 (CVE-2023-3022) - CVE-2023-3022 kernel: IPv6: panic in fib6_rule_suppress when fib6_rule_lookup fails
Summary: CVE-2023-3022 kernel: IPv6: panic in fib6_rule_suppress when fib6_rule_lookup...
Keywords:
Status: NEW
Alias: CVE-2023-3022
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Nobody
QA Contact:
URL:
Whiteboard:
Depends On: 2006441 2167604 2175952 2211457 2211461 2211462 2211463
Blocks: 2176407
TreeView+ depends on / blocked
 
Reported: 2023-05-31 16:21 UTC by Alex
Modified: 2025-01-27 13:17 UTC (History)
43 users (show)

Fixed In Version: kernel 5.2-rc1
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Alex 2023-05-31 16:21:34 UTC
A flaw in the Linux Kernel found. If IPV6 being used in the way that some specific networking local rule enabled and both IPV6 being used, then it can lead to Kernel crash with the message "fib6_rule_suppress+0x22". It happens when receiving some networking packet to the local IPV6 address that matches this specific rule.

References:
https://github.com/torvalds/linux/commit/a65120bae4b7
https://bugzilla.redhat.com/show_bug.cgi?id=2175952
https://bugzilla.redhat.com/show_bug.cgi?id=2167604
https://bugzilla.redhat.com/show_bug.cgi?id=2140599#c13

Comment 1 Alex 2023-05-31 17:03:58 UTC
Created kernel tracking bugs for this issue:

Affects: fedora-all [bug 2211457]

Comment 10 Justin M. Forbes 2023-06-05 12:28:50 UTC
This was fixed for Fedora in the 5.2 stable kernel rebases.

Comment 12 Mauro Matteo Cascella 2023-06-19 09:13:13 UTC
This issue was fixed upstream in version 5.2-rc1. The kernel packages as shipped in the following Red Hat products were previously updated to a version that contains the fix via the following errata:

kernel in Red Hat Enterprise Linux 8.6 Extended Update Support
https://access.redhat.com/errata/RHSA-2023:1130

kernel-rt in Red Hat Enterprise Linux 8
https://access.redhat.com/errata/RHSA-2022:1975

Comment 15 LeuCanh 2023-11-16 04:37:22 UTC Comment hidden (spam)
Comment 16 potefa 2024-01-02 08:58:50 UTC Comment hidden (spam)
Comment 17 anbbcsk317 2024-01-09 09:23:57 UTC Comment hidden (spam)
Comment 18 anbbcsk317 2024-01-09 09:24:45 UTC Comment hidden (spam)
Comment 19 wunschtaria 2024-01-31 07:25:08 UTC Comment hidden (spam)
Comment 21 blorian 2024-11-28 11:32:42 UTC Comment hidden (spam)
Comment 22 Rowanl Lebsackl 2024-12-05 04:39:33 UTC Comment hidden (spam)
Comment 23 azizgarbayo 2024-12-12 08:12:51 UTC Comment hidden (spam)

Note You need to log in before you can comment on or make changes to this bug.