CVE-2013-4125
published 2013-07-15CVE-2013-4125: The fib6_add_rt2node function in net/ipv6/ip6_fib.c in the IPv6 stack in the Linux kernel through 3.10.1 does not properly handle Router Advertisement (RA)…
PriorityP429medium5.4CVSS 2.0
AVNACHAuNCNINAC
EPSS
4.67%
90.9th percentile
The fib6_add_rt2node function in net/ipv6/ip6_fib.c in the IPv6 stack in the Linux kernel through 3.10.1 does not properly handle Router Advertisement (RA) messages in certain circumstances involving three routes that initially qualified for membership in an ECMP route set until a change occurred for one of the first two routes, which allows remote attackers to cause a denial of service (system crash) via a crafted sequence of messages.
Affected
215 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.10.5-1 (bookworm) | linux 3.10.5-1 (bookworm) |
| linux | linux_kernel | <= 3.10.1 | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
CVSS provenance
nvdv2.05.4MEDIUMAV:N/AC:H/Au:N/C:N/I:N/A:C
osv5.4MEDIUM
vendor_ubuntu7.8HIGH
vendor_debian5.4MEDIUM
vendor_redhat5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (Raring HWE) vulnerabilities
vendor_ubuntu·2013-08-20·CVSS 7.8
CVE-2013-1059 [HIGH] Linux kernel (Raring HWE) vulnerabilities
Title: Linux kernel (Raring HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Chanam Park reported a Null pointer flaw in the Linux kernel's Ceph client.
A remote attacker could exploit this flaw to cause a denial of service
(system crash). (CVE-2013-1059)
An information leak was discovered in the Linux kernel's fanotify
interface. A local user could exploit this flaw to obtain sensitive
information from kernel memory. (CVE-2013-2148)
Jonathan Salwan discovered an information leak in the Linux kernel's cdrom
driver. A local user can exploit this leak to obtain sensitive information
from kernel memory if the CD-ROM drive is malfunctioning. (CVE-2013-2164)
Kees Cook discovered a format string vulnerability in the Linux kernel's
disk block layer. A local use
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2013-08-20·CVSS 7.8
CVE-2013-1059 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Chanam Park reported a Null pointer flaw in the Linux kernel's Ceph client.
A remote attacker could exploit this flaw to cause a denial of service
(system crash). (CVE-2013-1059)
An information leak was discovered in the Linux kernel's fanotify
interface. A local user could exploit this flaw to obtain sensitive
information from kernel memory. (CVE-2013-2148)
Jonathan Salwan discovered an information leak in the Linux kernel's cdrom
driver. A local user can exploit this leak to obtain sensitive information
from kernel memory if the CD-ROM drive is malfunctioning. (CVE-2013-2164)
Kees Cook discovered a format string vulnerability in the Linux kernel's
disk block layer. A local user with admini
Red Hat
kernel: ipv6: BUG_ON in fib6_add_rt2node()
vendor_redhat·2013-07-15·CVSS 5.4
CVE-2013-4125 [MEDIUM] kernel: ipv6: BUG_ON in fib6_add_rt2node()
kernel: ipv6: BUG_ON in fib6_add_rt2node()
The fib6_add_rt2node function in net/ipv6/ip6_fib.c in the IPv6 stack in the Linux kernel through 3.10.1 does not properly handle Router Advertisement (RA) messages in certain circumstances involving three routes that initially qualified for membership in an ECMP route set until a change occurred for one of the first two routes, which allows remote attackers to cause a denial of service (system crash) via a crafted sequence of messages.
Statement: Not vulnerable.
This issue did not affect the kernel packages as shipped with Red Hat Enterprise Linux 5, 6 and Red Hat Enterprise MRG 2.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux
Debian
CVE-2013-4125: linux - The fib6_add_rt2node function in net/ipv6/ip6_fib.c in the IPv6 stack in the Lin...
vendor_debian·2013·CVSS 5.4
CVE-2013-4125 [MEDIUM] CVE-2013-4125: linux - The fib6_add_rt2node function in net/ipv6/ip6_fib.c in the IPv6 stack in the Lin...
The fib6_add_rt2node function in net/ipv6/ip6_fib.c in the IPv6 stack in the Linux kernel through 3.10.1 does not properly handle Router Advertisement (RA) messages in certain circumstances involving three routes that initially qualified for membership in an ECMP route set until a change occurred for one of the first two routes, which allows remote attackers to cause a denial of service (system crash) via a crafted sequence of messages.
Scope: local
bookworm: resolved (fixed in 3.10.5-1)
bullseye: resolved (fixed in 3.10.5-1)
forky: resolved (fixed in 3.10.5-1)
sid: resolved (fixed in 3.10.5-1)
trixie: resolved (fixed in 3.10.5-1)
GHSA
GHSA-q98v-4qrj-cxm4: The fib6_add_rt2node function in net/ipv6/ip6_fib
ghsa_unreviewed·2022-05-17
CVE-2013-4125 [MEDIUM] GHSA-q98v-4qrj-cxm4: The fib6_add_rt2node function in net/ipv6/ip6_fib
The fib6_add_rt2node function in net/ipv6/ip6_fib.c in the IPv6 stack in the Linux kernel through 3.10.1 does not properly handle Router Advertisement (RA) messages in certain circumstances involving three routes that initially qualified for membership in an ECMP route set until a change occurred for one of the first two routes, which allows remote attackers to cause a denial of service (system crash) via a crafted sequence of messages.
OSV
CVE-2013-4125: The fib6_add_rt2node function in net/ipv6/ip6_fib
osv·2013-07-15·CVSS 5.4
CVE-2013-4125 [MEDIUM] CVE-2013-4125: The fib6_add_rt2node function in net/ipv6/ip6_fib
The fib6_add_rt2node function in net/ipv6/ip6_fib.c in the IPv6 stack in the Linux kernel through 3.10.1 does not properly handle Router Advertisement (RA) messages in certain circumstances involving three routes that initially qualified for membership in an ECMP route set until a change occurred for one of the first two routes, which allows remote attackers to cause a denial of service (system crash) via a crafted sequence of messages.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-4125 kernel: kernel: ipv6: BUG_ON in fib6_add_rt2node() [fedora-all]
bugzilla·2013-07-15·CVSS 5.4
CVE-2013-4125 [MEDIUM] CVE-2013-4125 kernel: kernel: ipv6: BUG_ON in fib6_add_rt2node() [fedora-all]
CVE-2013-4125 kernel: kernel: ipv6: BUG_ON in fib6_add_rt2node() [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue aff
Bugzilla
CVE-2013-4125 kernel: ipv6: BUG_ON in fib6_add_rt2node()
bugzilla·2013-07-15·CVSS 5.4
CVE-2013-4125 [MEDIUM] CVE-2013-4125 kernel: ipv6: BUG_ON in fib6_add_rt2node()
CVE-2013-4125 kernel: ipv6: BUG_ON in fib6_add_rt2node()
If two router advertisment speaker announce seperate default gateways with infinite timeout the kernel currently packs these routes together into an ecmp route set. If one of the RA speaker now changes the advertised expiration to a lower value and a third route with infinite timeout pops up we end up with a BUG_ON.
Remote attacker could use this flaw to crash the system.
Fixed by:
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=307f2fb95e9b96b3577916e73d92e104f8f26494
Introduced by:
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=51ebd3181572af8d5076808dab2682d800f6da5d
Introduced in upstream version:
v3.7-rc1
Acknowledgements:
Red Hat would like to thank Hannes Frederic Sow
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=307f2fb95e9b96b3577916e73d92e104f8f26494http://lists.fedoraproject.org/pipermail/package-announce/2013-July/112454.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-July/112619.htmlhttp://www.openwall.com/lists/oss-security/2013/07/15/4http://www.securityfocus.com/bid/61166http://www.securitytracker.com/id/1028780https://bugzilla.redhat.com/show_bug.cgi?id=984664https://exchange.xforce.ibmcloud.com/vulnerabilities/85645https://github.com/torvalds/linux/commit/307f2fb95e9b96b3577916e73d92e104f8f26494http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=307f2fb95e9b96b3577916e73d92e104f8f26494http://lists.fedoraproject.org/pipermail/package-announce/2013-July/112454.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-July/112619.htmlhttp://www.openwall.com/lists/oss-security/2013/07/15/4http://www.securityfocus.com/bid/61166http://www.securitytracker.com/id/1028780https://bugzilla.redhat.com/show_bug.cgi?id=984664https://exchange.xforce.ibmcloud.com/vulnerabilities/85645https://github.com/torvalds/linux/commit/307f2fb95e9b96b3577916e73d92e104f8f26494
2013-07-15
Published