Bug 871848 (CVE-2012-4565) - CVE-2012-4565 kernel: net: divide by zero in tcp algorithm illinois
Summary: CVE-2012-4565 kernel: net: divide by zero in tcp algorithm illinois
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2012-4565
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 866514 866518 871920 871921 871922 871923
Blocks: 871849
TreeView+ depends on / blocked
 
Reported: 2012-10-31 14:21 UTC by Petr Matousek
Modified: 2019-09-29 12:57 UTC (History)
25 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2013-06-05 18:58:11 UTC


Attachments (Terms of Use)


Links
System ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2012:1491 normal SHIPPED_LIVE Important: kernel-rt security and bug fix update 2012-12-05 00:50:25 UTC
Red Hat Product Errata RHSA-2012:1580 normal SHIPPED_LIVE Moderate: kernel security, bug fix and enhancement update 2012-12-19 03:31:48 UTC

Description Petr Matousek 2012-10-31 14:21:36 UTC
Reading TCP stats when using TCP Illinois congestion control algorithm can cause a divide by zero kernel oops.

An unprivileged local user could use this flaw to crash the system.

Proposed upstream patch:
http://thread.gmane.org/gmane.linux.network/247871

Acknowledgements:

This issue was discovered by Rodrigo Freire of Red Hat.

Comment 3 Petr Matousek 2012-10-31 17:52:45 UTC
Created kernel tracking bugs for this issue

Affects: fedora-all [bug 871923]

Comment 4 Petr Matousek 2012-10-31 18:04:06 UTC
Statement:

This issue did not affect the version of Linux kernel as shipped with Red Hat Enterprise Linux 5.

This issue did affect the version of Linux kernel as shipped with Red Hat Enterprise Linux 6.

This issue did affect the version of Linux kernel as shipped with Red Hat Enterprise MRG 2.

Comment 6 errata-xmlrpc 2012-12-04 20:04:08 UTC
This issue has been addressed in following products:

  MRG for RHEL-6 v.2

Via RHSA-2012:1491 https://rhn.redhat.com/errata/RHSA-2012-1491.html

Comment 7 John Kacur 2012-12-17 15:16:01 UTC
I believe this is
commit dee1f973ca341c266229faa5a1a5bb268bed3531 upstream

Comment 8 errata-xmlrpc 2012-12-18 22:36:20 UTC
This issue has been addressed in following products:

  Red Hat Enterprise Linux 6

Via RHSA-2012:1580 https://rhn.redhat.com/errata/RHSA-2012-1580.html


Note You need to log in before you can comment on or make changes to this bug.