CVE-2013-4563
published 2013-11-20CVE-2013-4563: The udp6_ufo_fragment function in net/ipv6/udp_offload.c in the Linux kernel through 3.12, when UDP Fragmentation Offload (UFO) is enabled, does not properly…
PriorityP431high7.1CVSS 2.0
AVNACMAuNCNINAC
EPSS
3.90%
89.2th percentile
The udp6_ufo_fragment function in net/ipv6/udp_offload.c in the Linux kernel through 3.12, when UDP Fragmentation Offload (UFO) is enabled, does not properly perform a certain size comparison before inserting a fragment header, which allows remote attackers to cause a denial of service (panic) via a large IPv6 UDP packet, as demonstrated by use of the Token Bucket Filter (TBF) queueing discipline.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | linux | < linux 3.11.10-1 (bookworm) | linux 3.11.10-1 (bookworm) |
| linux | linux_kernel | >= 0 < 3.11.10-1 | 3.11.10-1 |
| linux | linux_kernel | >= 0 < 3.11.10-1 | 3.11.10-1 |
| linux | linux_kernel | >= 0 < 3.11.10-1 | 3.11.10-1 |
| linux | linux_kernel | >= 0 < 3.11.10-1 | 3.11.10-1 |
| linux | linux_kernel | >= 3.11 < 3.12.4 | 3.12.4 |
| linux | linux_kernel | 3.9.8 – 3.10.23 | — |
CVSS provenance
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
vendor_ubuntu7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (Saucy HWE) vulnerabilities
vendor_ubuntu·2014-02-18·CVSS 7.1
CVE-2013-4563 [HIGH] Linux kernel (Saucy HWE) vulnerabilities
Title: Linux kernel (Saucy HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Saran Neti reported a flaw in the ipv6 UDP Fragmentation Offload (UFI) in
the Linux kernel. A remote attacker could exploit this flaw to cause a
denial of service (panic). (CVE-2013-4563)
Mathy Vanhoef discovered an error in the the way the ath9k driver was
handling the BSSID masking. A remote attacker could exploit this error to
discover the original MAC address after a spoofing atack. (CVE-2013-4579)
Andrew Honig reported a flaw in the Linux Kernel's kvm_vm_ioctl_create_vcpu
function of the Kernel Virtual Machine (KVM) subsystem. A local user could
exploit this flaw to gain privileges on the host machine. (CVE-2013-4587)
Andrew Honig reported a flaw in the apic_get_tmcct functi
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-02-18·CVSS 7.1
CVE-2013-4563 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Saran Neti reported a flaw in the ipv6 UDP Fragmentation Offload (UFI) in
the Linux kernel. A remote attacker could exploit this flaw to cause a
denial of service (panic). (CVE-2013-4563)
Mathy Vanhoef discovered an error in the the way the ath9k driver was
handling the BSSID masking. A remote attacker could exploit this error to
discover the original MAC address after a spoofing atack. (CVE-2013-4579)
Andrew Honig reported a flaw in the Linux Kernel's kvm_vm_ioctl_create_vcpu
function of the Kernel Virtual Machine (KVM) subsystem. A local user could
exploit this flaw to gain privileges on the host machine. (CVE-2013-4587)
Andrew Honig reported a flaw in the apic_get_tmcct function of the Ke
Red Hat
kernel: net: large udp packet over IPv6 over UFO-enabled device with TBF qdisc panic
vendor_redhat·2013-10-29·CVSS 7.1
CVE-2013-4563 [HIGH] kernel: net: large udp packet over IPv6 over UFO-enabled device with TBF qdisc panic
kernel: net: large udp packet over IPv6 over UFO-enabled device with TBF qdisc panic
The udp6_ufo_fragment function in net/ipv6/udp_offload.c in the Linux kernel through 3.12, when UDP Fragmentation Offload (UFO) is enabled, does not properly perform a certain size comparison before inserting a fragment header, which allows remote attackers to cause a denial of service (panic) via a large IPv6 UDP packet, as demonstrated by use of the Token Bucket Filter (TBF) queueing discipline.
Statement: Not vulnerable.
This issue did not affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 5, 6 and Red Hat Enterprise MRG 2.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterpris
Debian
CVE-2013-4563: linux - The udp6_ufo_fragment function in net/ipv6/udp_offload.c in the Linux kernel thr...
vendor_debian·2013·CVSS 7.1
CVE-2013-4563 [HIGH] CVE-2013-4563: linux - The udp6_ufo_fragment function in net/ipv6/udp_offload.c in the Linux kernel thr...
The udp6_ufo_fragment function in net/ipv6/udp_offload.c in the Linux kernel through 3.12, when UDP Fragmentation Offload (UFO) is enabled, does not properly perform a certain size comparison before inserting a fragment header, which allows remote attackers to cause a denial of service (panic) via a large IPv6 UDP packet, as demonstrated by use of the Token Bucket Filter (TBF) queueing discipline.
Scope: local
bookworm: resolved (fixed in 3.11.10-1)
bullseye: resolved (fixed in 3.11.10-1)
forky: resolved (fixed in 3.11.10-1)
sid: resolved (fixed in 3.11.10-1)
trixie: resolved (fixed in 3.11.10-1)
GHSA
GHSA-8qgm-44j9-8vrh: The udp6_ufo_fragment function in net/ipv6/udp_offload
ghsa_unreviewed·2022-05-17
CVE-2013-4563 [HIGH] GHSA-8qgm-44j9-8vrh: The udp6_ufo_fragment function in net/ipv6/udp_offload
The udp6_ufo_fragment function in net/ipv6/udp_offload.c in the Linux kernel through 3.12, when UDP Fragmentation Offload (UFO) is enabled, does not properly perform a certain size comparison before inserting a fragment header, which allows remote attackers to cause a denial of service (panic) via a large IPv6 UDP packet, as demonstrated by use of the Token Bucket Filter (TBF) queueing discipline.
OSV
CVE-2013-4563: The udp6_ufo_fragment function in net/ipv6/udp_offload
osv·2013-11-20·CVSS 7.1
CVE-2013-4563 [HIGH] CVE-2013-4563: The udp6_ufo_fragment function in net/ipv6/udp_offload
The udp6_ufo_fragment function in net/ipv6/udp_offload.c in the Linux kernel through 3.12, when UDP Fragmentation Offload (UFO) is enabled, does not properly perform a certain size comparison before inserting a fragment header, which allows remote attackers to cause a denial of service (panic) via a large IPv6 UDP packet, as demonstrated by use of the Token Bucket Filter (TBF) queueing discipline.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-4563 kernel: net: large udp packet over IPv6 over UFO-enabled device with TBF qdisc panic
bugzilla·2013-11-13·CVSS 7.1
CVE-2013-4563 [HIGH] CVE-2013-4563 kernel: net: large udp packet over IPv6 over UFO-enabled device with TBF qdisc panic
CVE-2013-4563 kernel: net: large udp packet over IPv6 over UFO-enabled device with TBF qdisc panic
Commit 1e2bd517c108816220f262d7954b697af03b5f9c ("udp6: Fix udp
fragmentation for tunnel traffic.") changed the calculation if
there is enough space to include a fragment header in the skb from a
skb->mac_header dervived one to skb_headroom. Because we already peeled
off the skb to transport_header this is wrong.
This fixes a panic Saran Neti reported. He used the tbf scheduler which
skb_gso_segments the skb. The offsets get negative and we panic in memcpy
because the skb was erroneously not expanded at the head.
Introduced by:
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=1e2bd517c108816220f262d7954b697af03b5f9c
Introduced in:
v3.10-rc5
Upstream fix:
http://g
Bugzilla
CVE-2013-4563 kernel: net: large udp packet over IPv6 over UFO-enabled device with TBF qdisc panic [fedora-all]
bugzilla·2013-11-13·CVSS 7.1
CVE-2013-4563 [HIGH] CVE-2013-4563 kernel: net: large udp packet over IPv6 over UFO-enabled device with TBF qdisc panic [fedora-all]
CVE-2013-4563 kernel: net: large udp packet over IPv6 over UFO-enabled device with TBF qdisc panic [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when avail
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=0e033e04c2678dbbe74a46b23fffb7bb918c288ehttp://lists.opensuse.org/opensuse-security-announce/2014-02/msg00003.htmlhttp://www.openwall.com/lists/oss-security/2013/11/13/9http://www.ubuntu.com/usn/USN-2113-1http://www.ubuntu.com/usn/USN-2117-1https://bugzilla.redhat.com/show_bug.cgi?id=1030015https://github.com/torvalds/linux/commit/0e033e04c2678dbbe74a46b23fffb7bb918c288ehttp://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=0e033e04c2678dbbe74a46b23fffb7bb918c288ehttp://lists.opensuse.org/opensuse-security-announce/2014-02/msg00003.htmlhttp://www.openwall.com/lists/oss-security/2013/11/13/9http://www.ubuntu.com/usn/USN-2113-1http://www.ubuntu.com/usn/USN-2117-1https://bugzilla.redhat.com/show_bug.cgi?id=1030015https://github.com/torvalds/linux/commit/0e033e04c2678dbbe74a46b23fffb7bb918c288e
2013-11-20
Published