Bug 865492 - (CVE-2012-4517) CVE-2012-4517 ibacm: DoS (ibacm deamon crash) by joining responses for multicast destinations
CVE-2012-4517 ibacm: DoS (ibacm deamon crash) by joining responses for multic...
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
All Linux
low Severity low
: ---
: ---
Assigned To: Red Hat Product Security
: Security
Depends On: 866222
Blocks: 855229 865513
  Show dependency treegraph
Reported: 2012-10-11 11:02 EDT by Jan Lieskovsky
Modified: 2015-10-23 11:01 EDT (History)
3 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
: 866222 (view as bug list)
Last Closed: 2015-08-22 10:54:33 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

  None (edit)
Description Jan Lieskovsky 2012-10-11 11:02:50 EDT
A denial of service flaw was found in the way ibacm, an InfiniBand communication manager assistant, performed management of reference counts for multicast connections. The default reference count value for multicast connection is set to zero and when the multicast connection got released, an attempt was made to free it, possibly resulting in ib_acm service / daemon crash.

Upstream patch:
[1] http://git.openfabrics.org/git?p=~shefty/ibacm.git;a=commit;h=c7d28b35d64333c262de3ec972c426423dadccf9
Comment 1 Jan Lieskovsky 2012-10-11 11:04:19 EDT
This issue affects the version of the ibacm package, as shipped with Red Hat Enterprise Linux 6.
Comment 2 Jan Lieskovsky 2012-10-11 11:51:57 EDT
CVE Request:
[2] http://www.openwall.com/lists/oss-security/2012/10/11/6
Comment 3 Vincent Danen 2012-10-11 17:17:28 EDT
This was assigned CVE-2012-4517.
Comment 6 errata-xmlrpc 2013-02-21 04:48:44 EST
This issue has been addressed in following products:

  Red Hat Enterprise Linux 6

Via RHSA-2013:0509 https://rhn.redhat.com/errata/RHSA-2013-0509.html
Comment 7 Huzaifa S. Sidhpurwala 2013-02-21 23:46:51 EST


Note You need to log in before you can comment on or make changes to this bug.