CVE-2011-3188
published 2012-05-24CVE-2011-3188: The (1) IPv4 and (2) IPv6 implementations in the Linux kernel before 3.1 use a modified MD4 algorithm to generate sequence numbers and Fragment Identification…
PriorityP346critical9.1CVSS 3.1
AVNACLPRNUINSUCNIHAH
EPSS
5.80%
92.3th percentile
The (1) IPv4 and (2) IPv6 implementations in the Linux kernel before 3.1 use a modified MD4 algorithm to generate sequence numbers and Fragment Identification values, which makes it easier for remote attackers to cause a denial of service (disrupted networking) or hijack network sessions by predicting these values and sending crafted packets.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | arx | 6.0.0 – 6.4.0 | — |
| f5 | big-ip_access_policy_manager | 10.1.0 – 10.2.4 | — |
| f5 | big-ip_access_policy_manager | 11.0.0 – 11.1.0 | — |
| f5 | big-ip_analytics | 11.0.0 – 11.1.0 | — |
| f5 | big-ip_application_security_manager | 10.0.0 – 10.2.4 | — |
| f5 | big-ip_application_security_manager | 11.0.0 – 11.1.0 | — |
| f5 | big-ip_edge_gateway | 10.1.0 – 10.2.4 | — |
| f5 | big-ip_edge_gateway | 11.0.0 – 11.1.0 | — |
| f5 | big-ip_global_traffic_manager | 10.0.0 – 10.2.4 | — |
| f5 | big-ip_global_traffic_manager | 11.0.0 – 11.1.0 | — |
| f5 | big-ip_link_controller | 10.0.0 – 10.2.4 | — |
| f5 | big-ip_link_controller | 11.0.0 – 11.1.0 | — |
| f5 | big-ip_local_traffic_manager | 10.0.0 – 10.2.4 | — |
| f5 | big-ip_local_traffic_manager | 11.0.0 – 11.1.0 | — |
| f5 | big-ip_protocol_security_module | 10.0.0 – 10.2.4 | — |
| f5 | big-ip_protocol_security_module | 11.0.0 – 11.1.0 | — |
| f5 | big-ip_wan_optimization_manager | 10.0.0 – 10.2.4 | — |
| f5 | big-ip_wan_optimization_manager | 11.0.0 – 11.1.0 | — |
| f5 | big-ip_webaccelerator | 10.0.0 – 10.2.4 | — |
| f5 | big-ip_webaccelerator | 11.0.0 – 11.1.0 | — |
| f5 | enterprise_manager | — | — |
| f5 | enterprise_manager | 2.1.0 – 2.3.0 | — |
| f5 | firepass | — | — |
| f5 | firepass | 6.0.0 – 6.1.0 | — |
| linux | linux_kernel | < 3.1 | 3.1 |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:P
vendor_redhat9.1CRITICAL
vendor_ubuntu6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-93rr-wh56-p8fw: The (1) IPv4 and (2) IPv6 implementations in the Linux kernel before 3
ghsa_unreviewed·2022-05-13
CVE-2011-3188 [CRITICAL] GHSA-93rr-wh56-p8fw: The (1) IPv4 and (2) IPv6 implementations in the Linux kernel before 3
The (1) IPv4 and (2) IPv6 implementations in the Linux kernel before 3.1 use a modified MD4 algorithm to generate sequence numbers and Fragment Identification values, which makes it easier for remote attackers to cause a denial of service (disrupted networking) or hijack network sessions by predicting these values and sending crafted packets.
Ubuntu
Linux kernel (Natty backport) vulnerabilities
vendor_ubuntu·2011-11-09·CVSS 4.6
CVE-2011-1020 [MEDIUM] Linux kernel (Natty backport) vulnerabilities
Title: Linux kernel (Natty backport) vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that the /proc filesystem did not correctly handle
permission changes when programs executed. A local attacker could hold open
files to examine details about programs running with higher privileges,
potentially increasing the chances of exploiting additional
vulnerabilities. (CVE-2011-1020)
Vasiliy Kulikov discovered that the Bluetooth stack did not correctly clear
memory. A local attacker could exploit this to read kernel stack memory,
leading to a loss of privacy. (CVE-2011-1078)
Vasiliy Kulikov discovered that the Bluetooth stack did not correctly check
that device name strings were NULL terminated. A local attacker could
exploit this to crash the system,
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2011-11-08·CVSS 5.7
CVE-2011-1576 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Ryan Sweat discovered that the kernel incorrectly handled certain VLAN
packets. On some systems, a remote attacker could send specially crafted
traffic to crash the system, leading to a denial of service.
(CVE-2011-1576)
Vasiliy Kulikov and Dan Rosenberg discovered that ecryptfs did not
correctly check the origin of mount points. A local attacker could exploit
this to trick the system into unmounting arbitrary mount points, leading to
a denial of service. (CVE-2011-1833)
Vasiliy Kulikov discovered that taskstats did not enforce access
restrictions. A local attacker could exploit this to read certain
information, leading to a loss of privacy. (CVE-2011-2494)
Vasiliy Kulikov discovered that /p
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2011-10-25·CVSS 4.9
CVE-2011-2213 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Dan Rosenberg discovered that the IPv4 diagnostic routines did not
correctly validate certain requests. A local attacker could exploit this to
consume CPU resources, leading to a denial of service. (CVE-2011-2213)
Dan Rosenberg discovered that the Bluetooth stack incorrectly handled
certain L2CAP requests. If a system was using Bluetooth, a remote attacker
could send specially crafted traffic to crash the system or gain root
privileges. (CVE-2011-2497)
It was discovered that the EXT4 filesystem contained multiple off-by-one
flaws. A local attacker could exploit this to crash the system, leading to
a denial of service. (CVE-2011-2695)
Mauro Carvalho Chehab discovered that the si4713 radio dri
Ubuntu
Linux kernel (Maverick backport) vulnerabilities
vendor_ubuntu·2011-10-25·CVSS 4.9
CVE-2011-1479 [MEDIUM] Linux kernel (Maverick backport) vulnerabilities
Title: Linux kernel (Maverick backport) vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that the security fix for CVE-2010-4250 introduced a
regression. A remote attacker could exploit this to crash the system,
leading to a denial of service. (CVE-2011-1479)
Vasiliy Kulikov discovered that taskstats did not enforce access
restrictions. A local attacker could exploit this to read certain
information, leading to a loss of privacy. (CVE-2011-2494)
Vasiliy Kulikov discovered that /proc/PID/io did not enforce access
restrictions. A local attacker could exploit this to read certain
information, leading to a loss of privacy. (CVE-2011-2495)
It was discovered that the EXT4 filesystem contained multiple off-by-one
flaws. A local attacker could explo
Ubuntu
Linux kernel (Marvell DOVE) vulnerabilities
vendor_ubuntu·2011-10-25·CVSS 5.7
CVE-2011-1576 [MEDIUM] Linux kernel (Marvell DOVE) vulnerabilities
Title: Linux kernel (Marvell DOVE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Ryan Sweat discovered that the kernel incorrectly handled certain VLAN
packets. On some systems, a remote attacker could send specially crafted
traffic to crash the system, leading to a denial of service.
(CVE-2011-1576)
Vasiliy Kulikov and Dan Rosenberg discovered that ecryptfs did not
correctly check the origin of mount points. A local attacker could exploit
this to trick the system into unmounting arbitrary mount points, leading to
a denial of service. (CVE-2011-1833)
Vasiliy Kulikov discovered that taskstats did not enforce access
restrictions. A local attacker could exploit this to read certain
information, leading to a loss of privacy. (CVE-2011-2494)
Vasiliy Kulikov dis
Ubuntu
Linux kernel (EC2) vulnerabilities
vendor_ubuntu·2011-10-25·CVSS 5.7
CVE-2011-1576 [MEDIUM] Linux kernel (EC2) vulnerabilities
Title: Linux kernel (EC2) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Ryan Sweat discovered that the kernel incorrectly handled certain VLAN
packets. On some systems, a remote attacker could send specially crafted
traffic to crash the system, leading to a denial of service.
(CVE-2011-1576)
Vasiliy Kulikov and Dan Rosenberg discovered that ecryptfs did not
correctly check the origin of mount points. A local attacker could exploit
this to trick the system into unmounting arbitrary mount points, leading to
a denial of service. (CVE-2011-1833)
Vasiliy Kulikov discovered that taskstats did not enforce access
restrictions. A local attacker could exploit this to read certain
information, leading to a loss of privacy. (CVE-2011-2494)
Vasiliy Kulikov discovered t
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2011-10-25·CVSS 4.9
CVE-2011-1479 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that the security fix for CVE-2010-4250 introduced a
regression. A remote attacker could exploit this to crash the system,
leading to a denial of service. (CVE-2011-1479)
Vasiliy Kulikov discovered that taskstats did not enforce access
restrictions. A local attacker could exploit this to read certain
information, leading to a loss of privacy. (CVE-2011-2494)
Vasiliy Kulikov discovered that /proc/PID/io did not enforce access
restrictions. A local attacker could exploit this to read certain
information, leading to a loss of privacy. (CVE-2011-2495)
It was discovered that the EXT4 filesystem contained multiple off-by-one
flaws. A local attacker could exploit this to crash the
Ubuntu
Linux kernel (i.MX51) vulnerabilities
vendor_ubuntu·2011-10-25·CVSS 5.9
CVE-2011-1573 [MEDIUM] Linux kernel (i.MX51) vulnerabilities
Title: Linux kernel (i.MX51) vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that the Stream Control Transmission Protocol (SCTP)
implementation incorrectly calculated lengths. If the net.sctp.addip_enable
variable was turned on, a remote attacker could send specially crafted
traffic to crash the system. (CVE-2011-1573)
Ryan Sweat discovered that the kernel incorrectly handled certain VLAN
packets. On some systems, a remote attacker could send specially crafted
traffic to crash the system, leading to a denial of service.
(CVE-2011-1576)
Timo Warns discovered that the EFI GUID partition table was not correctly
parsed. A physically local attacker that could insert mountable devices
could exploit this to crash the system or possibly gain root p
Ubuntu
Linux kernel (Marvell DOVE) vulnerabilities
vendor_ubuntu·2011-10-25·CVSS 5.7
CVE-2011-1576 [MEDIUM] Linux kernel (Marvell DOVE) vulnerabilities
Title: Linux kernel (Marvell DOVE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Ryan Sweat discovered that the kernel incorrectly handled certain VLAN
packets. On some systems, a remote attacker could send specially crafted
traffic to crash the system, leading to a denial of service.
(CVE-2011-1576)
Vasiliy Kulikov and Dan Rosenberg discovered that ecryptfs did not
correctly check the origin of mount points. A local attacker could exploit
this to trick the system into unmounting arbitrary mount points, leading to
a denial of service. (CVE-2011-1833)
Vasiliy Kulikov discovered that taskstats did not enforce access
restrictions. A local attacker could exploit this to read certain
information, leading to a loss of privacy. (CVE-2011-2494)
Vasiliy Kulikov dis
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2011-10-20·CVSS 6.8
CVE-2011-2495 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Multiple kernel flaws have been fixed.
It was discovered that the Auerswald usb driver incorrectly handled lengths
of the USB string descriptors. A local attacker with physical access could
insert a specially crafted USB device and gain root privileges.
(CVE-2009-4067)
It was discovered that the Stream Control Transmission Protocol (SCTP)
implementation incorrectly calculated lengths. If the net.sctp.addip_enable
variable was turned on, a remote attacker could send specially crafted
traffic to crash the system. (CVE-2011-1573)
Vasiliy Kulikov discovered that taskstats did not enforce access
restrictions. A local attacker could exploit this to read certain
information, leading to a loss of privacy. (CVE-2011-2494)
Vasiliy Kulikov discovered
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2011-10-12·CVSS 6.1
CVE-2011-1776 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Timo Warns discovered that the EFI GUID partition table was not correctly
parsed. A physically local attacker that could insert mountable devices
could exploit this to crash the system or possibly gain root privileges.
(CVE-2011-1776)
Dan Rosenberg discovered that the IPv4 diagnostic routines did not
correctly validate certain requests. A local attacker could exploit this to
consume CPU resources, leading to a denial of service. (CVE-2011-2213)
Dan Rosenberg discovered that the Bluetooth stack incorrectly handled
certain L2CAP requests. If a system was using Bluetooth, a remote attacker
could send specially crafted traffic to crash the system or gain root
privileges. (CVE-2011-2497)
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2011-09-29·CVSS 5.7
CVE-2011-1576 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Multiple kernel flaws have been fixed.
Ryan Sweat discovered that the kernel incorrectly handled certain VLAN
packets. On some systems, a remote attacker could send specially crafted
traffic to crash the system, leading to a denial of service.
(CVE-2011-1576)
Timo Warns discovered that the EFI GUID partition table was not correctly
parsed. A physically local attacker that could insert mountable devices
could exploit this to crash the system or possibly gain root privileges.
(CVE-2011-1776)
Dan Rosenberg discovered that the IPv4 diagnostic routines did not
correctly validate certain requests. A local attacker could exploit this to
consume CPU resources, leading to a denial of service. (CVE-2011-2213)
Dan Rosenberg discovered that the
Red Hat
kernel: net: improve sequence number generation
vendor_redhat·2011-08-07·CVSS 9.1
CVE-2011-3188 [CRITICAL] kernel: net: improve sequence number generation
kernel: net: improve sequence number generation
The (1) IPv4 and (2) IPv6 implementations in the Linux kernel before 3.1 use a modified MD4 algorithm to generate sequence numbers and Fragment Identification values, which makes it easier for remote attackers to cause a denial of service (disrupted networking) or hijack network sessions by predicting these values and sending crafted packets.
Statement: This issue affects the Linux kernel as shipped with Red Hat Enterprise Linux 4, 5, 6, and Red Hat Enterprise MRG. It has been addressed in Red Hat Enterprise Linux 5, 6, and Red Hat Enterprise MRG via https://rhn.redhat.com/errata/RHSA-2011-1386.html, https://rhn.redhat.com/errata/RHSA-2011-1465.html, and https://rhn.redhat.com/errata/RHSA-2012-0010.html. Red Hat Enterprise Linux 4 is now in
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-3188 kernel: net: improve sequence number generation [fedora-all]
bugzilla·2011-10-25·CVSS 9.1
CVE-2011-3188 [CRITICAL] CVE-2011-3188 kernel: net: improve sequence number generation [fedora-all]
CVE-2011-3188 kernel: net: improve sequence number generation [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=732658
Please note: this issue affects multiple
Bugzilla
CVE-2011-3188 kernel: net: improve sequence number generation
bugzilla·2011-08-23·CVSS 9.1
CVE-2011-3188 [CRITICAL] CVE-2011-3188 kernel: net: improve sequence number generation
CVE-2011-3188 kernel: net: improve sequence number generation
Dan Kaminsky pointed out that using partial MD4 and using that to generate a sequence number, of which only 24-bits are truly unguessable, seriously undermine the goals of random sequence number generation.
In particular, with only 24-bits being truly unguessable, packet injection into a session using even something like brute force is a real potential possibility.
We only use 24-bits because we regenerate the random number every 5 minutes "just in case." But what does is trade a "we don't know" kind of theoretical issue for a provably real one (brute force attack).
Therefore [Dave Miller] moving us more in line with RFC1948 (as well as OpenBSD and Solaris), to use MD5 and a full 32-bit result in the generated sequence numbe
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=6e5714eaf77d79ae1c8b47e3e040ff5411b717echttp://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=bc0b96b54a21246e377122d54569eef71cec535fhttp://marc.info/?l=bugtraq&m=139447903326211&w=2http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.1http://www.openwall.com/lists/oss-security/2011/08/23/2https://bugzilla.redhat.com/show_bug.cgi?id=732658https://github.com/torvalds/linux/commit/6e5714eaf77d79ae1c8b47e3e040ff5411b717echttps://github.com/torvalds/linux/commit/bc0b96b54a21246e377122d54569eef71cec535fhttps://support.f5.com/csp/article/K15301?utm_source=f5support&%3Butm_medium=RSShttp://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=6e5714eaf77d79ae1c8b47e3e040ff5411b717echttp://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=bc0b96b54a21246e377122d54569eef71cec535fhttp://marc.info/?l=bugtraq&m=139447903326211&w=2http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.1http://www.openwall.com/lists/oss-security/2011/08/23/2https://bugzilla.redhat.com/show_bug.cgi?id=732658https://github.com/torvalds/linux/commit/6e5714eaf77d79ae1c8b47e3e040ff5411b717echttps://github.com/torvalds/linux/commit/bc0b96b54a21246e377122d54569eef71cec535fhttps://support.f5.com/csp/article/K15301?utm_source=f5support&%3Butm_medium=RSS
2012-05-24
Published