CVE-2015-2922
published 2015-05-27CVE-2015-2922: The ndisc_router_discovery function in net/ipv6/ndisc.c in the Neighbor Discovery (ND) protocol implementation in the IPv6 stack in the Linux kernel before…
PriorityP418low3.3CVSS 2.0
AVAACLAuNCNINAP
EPSS
3.05%
86.1th percentile
The ndisc_router_discovery function in net/ipv6/ndisc.c in the Neighbor Discovery (ND) protocol implementation in the IPv6 stack in the Linux kernel before 3.19.6 allows remote attackers to reconfigure a hop-limit setting via a small hop_limit value in a Router Advertisement (RA) message.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | linux | < linux 3.16.7-ckt9-1 (bookworm) | linux 3.16.7-ckt9-1 (bookworm) |
| debian | network-manager | < network-manager 1.0.2-1 (bookworm) | network-manager 1.0.2-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| android | — | — | |
| linux | linux_kernel | <= 3.19.5 | — |
| linux | linux_kernel | >= 0 < 3.16.7-ckt9-1 | 3.16.7-ckt9-1 |
| linux | linux_kernel | >= 0 < 3.16.7-ckt9-1 | 3.16.7-ckt9-1 |
| linux | linux_kernel | >= 0 < 3.16.7-ckt9-1 | 3.16.7-ckt9-1 |
| linux | linux_kernel | >= 0 < 3.16.7-ckt9-1 | 3.16.7-ckt9-1 |
| linux | linux_kernel | >= 0 < 3.13.0-51.84 | 3.13.0-51.84 |
| network-manager_project | network-manager | >= 0 < 1.0.2-1 | 1.0.2-1 |
| network-manager_project | network-manager | >= 0 < 1.0.2-1 | 1.0.2-1 |
| network-manager_project | network-manager | >= 0 < 1.0.2-1 | 1.0.2-1 |
| network-manager_project | network-manager | >= 0 < 1.0.2-1 | 1.0.2-1 |
| networkmanager_project | networkmanager | <= 1.0.7 | — |
| oracle | linux | — | — |
| oracle | solaris | — | — |
| redhat | enterprise_mrg | — | — |
CVSS provenance
nvdv2.03.3LOWAV:A/AC:L/Au:N/C:N/I:N/A:P
osv6.9MEDIUM
vendor_ubuntu6.9MEDIUM
vendor_debian3.3LOW
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-m83h-57fv-rrqc: The receive_ra function in rdisc/nm-lndp-rdisc
ghsa_unreviewed·2022-05-17·CVSS 3.3
CVE-2015-2924 [LOW] CWE-20 GHSA-m83h-57fv-rrqc: The receive_ra function in rdisc/nm-lndp-rdisc
The receive_ra function in rdisc/nm-lndp-rdisc.c in the Neighbor Discovery (ND) protocol implementation in the IPv6 stack in NetworkManager 1.x allows remote attackers to reconfigure a hop-limit setting via a small hop_limit value in a Router Advertisement (RA) message, a similar issue to CVE-2015-2922.
GHSA
GHSA-h2xq-wm46-j26f: The ndisc_router_discovery function in net/ipv6/ndisc
ghsa_unreviewed·2022-05-13
CVE-2015-2922 [LOW] GHSA-h2xq-wm46-j26f: The ndisc_router_discovery function in net/ipv6/ndisc
The ndisc_router_discovery function in net/ipv6/ndisc.c in the Neighbor Discovery (ND) protocol implementation in the IPv6 stack in the Linux kernel before 3.19.6 allows remote attackers to reconfigure a hop-limit setting via a small hop_limit value in a Router Advertisement (RA) message.
OSV
CVE-2015-2924: The receive_ra function in rdisc/nm-lndp-rdisc
osv·2015-11-16·CVSS 3.3
CVE-2015-2924 [LOW] CVE-2015-2924: The receive_ra function in rdisc/nm-lndp-rdisc
The receive_ra function in rdisc/nm-lndp-rdisc.c in the Neighbor Discovery (ND) protocol implementation in the IPv6 stack in NetworkManager 1.x allows remote attackers to reconfigure a hop-limit setting via a small hop_limit value in a Router Advertisement (RA) message, a similar issue to CVE-2015-2922.
OSV
CVE-2015-2922: The ndisc_router_discovery function in net/ipv6/ndisc
osv·2015-05-27·CVSS 3.3
CVE-2015-2922 [LOW] CVE-2015-2922: The ndisc_router_discovery function in net/ipv6/ndisc
The ndisc_router_discovery function in net/ipv6/ndisc.c in the Neighbor Discovery (ND) protocol implementation in the IPv6 stack in the Linux kernel before 3.19.6 allows remote attackers to reconfigure a hop-limit setting via a small hop_limit value in a Router Advertisement (RA) message.
OSV
linux vulnerabilities
osv·2015-04-30·CVSS 6.9
CVE-2015-2666 [MEDIUM] linux vulnerabilities
linux vulnerabilities
A stack overflow was discovered in the the microcode loader for the intel
x86 platform. A local attacker could exploit this flaw to cause a denial of
service (kernel crash) or to potentially execute code with kernel
privileges. (CVE-2015-2666)
It was discovered that the Linux kernel's IPv6 networking stack has a flaw
that allows using route advertisement (RA) messages to set the 'hop_limit'
to values that are too low. An unprivileged attacker on a local network
could exploit this flaw to cause a denial of service (IPv6 messages
dropped). (CVE-2015-2922)
OSV
linux-lts-utopic vulnerabilities
osv·2015-04-30·CVSS 4.9
CVE-2015-2150 [MEDIUM] linux-lts-utopic vulnerabilities
linux-lts-utopic vulnerabilities
Jan Beulich discovered the Xen virtual machine subsystem of the Linux
kernel did not properly restrict access to PCI command registers. A local
guest user could exploit this flaw to cause a denial of service (host
crash). (CVE-2015-2150)
A stack overflow was discovered in the the microcode loader for the intel
x86 platform. A local attacker could exploit this flaw to cause a denial of
service (kernel crash) or to potentially execute code with kernel
privileges. (CVE-2015-2666)
A privilege escalation was discovered in the fork syscall via the int80
entry on 64 bit kernels with 32 bit emulation support. An unprivileged
local attacker could exploit this flaw to increase their privileges on the
system. (CVE-2015-2830)
It was discovered that the Linux kernel
Android
CVE-2015-2922: Android Security Bulletin 2016-09-01
CVE: CVE-2015-2922
Severity: MEDIUM
References: A-29409847
Upstream
kernel
vendor_android·2016-09-01·CVSS 3.3
CVE-2015-2922 [LOW] CVE-2015-2922: Android Security Bulletin 2016-09-01
CVE: CVE-2015-2922
Severity: MEDIUM
References: A-29409847
Upstream
kernel
Android Security Bulletin 2016-09-01
CVE: CVE-2015-2922
Severity: MEDIUM
References: A-29409847
Upstream
kernel
Ubuntu
Linux kernel vulnerability
vendor_ubuntu·2015-04-30
CVE-2015-2922 Linux kernel vulnerability
Title: Linux kernel vulnerability
Summary: The system could be made to run programs as an administrator.
It was discovered that the Linux kernel's IPv6 networking stack has a flaw
that allows using route advertisement (RA) messages to set the 'hop_limit'
to values that are too low. An unprivileged attacker on a local network
could exploit this flaw to cause a denial of service (IPv6 messages
dropped).
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
we
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2015-04-30·CVSS 6.9
CVE-2015-2666 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
A stack overflow was discovered in the the microcode loader for the intel
x86 platform. A local attacker could exploit this flaw to cause a denial of
service (kernel crash) or to potentially execute code with kernel
privileges. (CVE-2015-2666)
It was discovered that the Linux kernel's IPv6 networking stack has a flaw
that allows using route advertisement (RA) messages to set the 'hop_limit'
to values that are too low. An unprivileged attacker on a local network
could exploit this flaw to cause a denial of service (IPv6 messages
dropped). (CVE-2015-2922)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoi
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2015-04-30·CVSS 4.9
CVE-2015-2150 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Jan Beulich discovered the Xen virtual machine subsystem of the Linux
kernel did not properly restrict access to PCI command registers. A local
guest user could exploit this flaw to cause a denial of service (host
crash). (CVE-2015-2150)
A stack overflow was discovered in the the microcode loader for the intel
x86 platform. A local attacker could exploit this flaw to cause a denial of
service (kernel crash) or to potentially execute code with kernel
privileges. (CVE-2015-2666)
A privilege escalation was discovered in the fork syscal vi the int80 entry
on 64 bit kernels with 32 bit emulation support. An unprivileged local
attacker could exploit this flaw to increase their privileges on the
sys
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2015-04-30·CVSS 6.9
CVE-2015-2666 [MEDIUM] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A stack overflow was discovered in the the microcode loader for the intel
x86 platform. A local attacker could exploit this flaw to cause a denial of
service (kernel crash) or to potentially execute code with kernel
privileges. (CVE-2015-2666)
It was discovered that the Linux kernel's IPv6 networking stack has a flaw
that allows using route advertisement (RA) messages to set the 'hop_limit'
to values that are too low. An unprivileged attacker on a local network
could exploit this flaw to cause a denial of service (IPv6 messages
dropped). (CVE-2015-2922)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due
Ubuntu
Linux kernel (Utopic HWE) vulnerabilities
vendor_ubuntu·2015-04-30·CVSS 4.9
CVE-2015-2150 [MEDIUM] Linux kernel (Utopic HWE) vulnerabilities
Title: Linux kernel (Utopic HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Jan Beulich discovered the Xen virtual machine subsystem of the Linux
kernel did not properly restrict access to PCI command registers. A local
guest user could exploit this flaw to cause a denial of service (host
crash). (CVE-2015-2150)
A stack overflow was discovered in the the microcode loader for the intel
x86 platform. A local attacker could exploit this flaw to cause a denial of
service (kernel crash) or to potentially execute code with kernel
privileges. (CVE-2015-2666)
A privilege escalation was discovered in the fork syscall via the int80
entry on 64 bit kernels with 32 bit emulation support. An unprivileged
local attacker could exploit this flaw to increase their privil
Ubuntu
Linux kernel (OMAP4) vulnerability
vendor_ubuntu·2015-04-30
CVE-2015-2922 Linux kernel (OMAP4) vulnerability
Title: Linux kernel (OMAP4) vulnerability
Summary: The system could be made to run programs as an administrator.
It was discovered that the Linux kernel's IPv6 networking stack has a flaw
that allows using route advertisement (RA) messages to set the 'hop_limit'
to values that are too low. An unprivileged attacker on a local network
could exploit this flaw to cause a denial of service (IPv6 messages
dropped).
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that packa
Red Hat
NetworkManager: denial of service (DoS) attack against IPv6 network stacks due to improper handling of Router Advertisements
vendor_redhat·2015-04-02·CVSS 3.3
CVE-2015-2924 [LOW] CWE-358 NetworkManager: denial of service (DoS) attack against IPv6 network stacks due to improper handling of Router Advertisements
NetworkManager: denial of service (DoS) attack against IPv6 network stacks due to improper handling of Router Advertisements
The receive_ra function in rdisc/nm-lndp-rdisc.c in the Neighbor Discovery (ND) protocol implementation in the IPv6 stack in NetworkManager 1.x allows remote attackers to reconfigure a hop-limit setting via a small hop_limit value in a Router Advertisement (RA) message, a similar issue to CVE-2015-2922.
A flaw was found in the way NetworkManager handled router advertisements. An unprivileged user on a local network could use IPv6 Neighbor Discovery ICMP to broadcast a non-route with a low hop limit, causing machines to lower the hop limit on existing IPv6 routes. If this limit is small enough, IPv6 packets would be dropped before reaching the final destination.
Pa
Red Hat
kernel: denial of service (DoS) attack against IPv6 network stacks due to improper handling of Router Advertisements.
vendor_redhat·2015-03-24·CVSS 3.3
CVE-2015-2922 [LOW] CWE-454 kernel: denial of service (DoS) attack against IPv6 network stacks due to improper handling of Router Advertisements.
kernel: denial of service (DoS) attack against IPv6 network stacks due to improper handling of Router Advertisements.
The ndisc_router_discovery function in net/ipv6/ndisc.c in the Neighbor Discovery (ND) protocol implementation in the IPv6 stack in the Linux kernel before 3.19.6 allows remote attackers to reconfigure a hop-limit setting via a small hop_limit value in a Router Advertisement (RA) message.
It was found that the Linux kernel's TCP/IP protocol suite implementation for IPv6 allowed the Hop Limit value to be set to a smaller value than the default one. An attacker on a local network could use this flaw to prevent systems on that network from sending or receiving network packets.
Statement: This issue affects the versions of the Linux kernel as shipped with
Red Hat Enterprise
Debian
CVE-2015-2924: network-manager - The receive_ra function in rdisc/nm-lndp-rdisc.c in the Neighbor Discovery (ND) ...
vendor_debian·2015·CVSS 3.3
CVE-2015-2924 [LOW] CVE-2015-2924: network-manager - The receive_ra function in rdisc/nm-lndp-rdisc.c in the Neighbor Discovery (ND) ...
The receive_ra function in rdisc/nm-lndp-rdisc.c in the Neighbor Discovery (ND) protocol implementation in the IPv6 stack in NetworkManager 1.x allows remote attackers to reconfigure a hop-limit setting via a small hop_limit value in a Router Advertisement (RA) message, a similar issue to CVE-2015-2922.
Scope: local
bookworm: resolved (fixed in 1.0.2-1)
bullseye: resolved (fixed in 1.0.2-1)
forky: resolved (fixed in 1.0.2-1)
sid: resolved (fixed in 1.0.2-1)
trixie: resolved (fixed in 1.0.2-1)
Debian
CVE-2015-2922: linux - The ndisc_router_discovery function in net/ipv6/ndisc.c in the Neighbor Discover...
vendor_debian·2015·CVSS 3.3
CVE-2015-2922 [LOW] CVE-2015-2922: linux - The ndisc_router_discovery function in net/ipv6/ndisc.c in the Neighbor Discover...
The ndisc_router_discovery function in net/ipv6/ndisc.c in the Neighbor Discovery (ND) protocol implementation in the IPv6 stack in the Linux kernel before 3.19.6 allows remote attackers to reconfigure a hop-limit setting via a small hop_limit value in a Router Advertisement (RA) message.
Scope: local
bookworm: resolved (fixed in 3.16.7-ckt9-1)
bullseye: resolved (fixed in 3.16.7-ckt9-1)
forky: resolved (fixed in 3.16.7-ckt9-1)
sid: resolved (fixed in 3.16.7-ckt9-1)
trixie: resolved (fixed in 3.16.7-ckt9-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-2924 NetworkManager: denial of service (DoS) attack against IPv6 network stacks due to improper handling of Router Advertisements
bugzilla·2015-04-08·CVSS 3.3
CVE-2015-2924 [LOW] CVE-2015-2924 NetworkManager: denial of service (DoS) attack against IPv6 network stacks due to improper handling of Router Advertisements
CVE-2015-2924 NetworkManager: denial of service (DoS) attack against IPv6 network stacks due to improper handling of Router Advertisements
This issue is similar to CVE-2015-2922 (bug 1203712).
This might refer to the code below:
http://cgit.freedesktop.org/NetworkManager/NetworkManager/tree/src/rdisc/nm-lndp-rdisc.c
...
hop_limit = ndp_msgra_curhoplimit (msgra);
if (rdisc->hop_limit != hop_limit) {
rdisc->hop_limit = hop_limit;
changed |= NM_RDISC_CONFIG_HOP_LIMIT;
...
CVE was assigned here: http://seclists.org/oss-sec/2015/q2/46
Discussion:
Created NetworkManager tracking bugs for this issue:
Affects: fedora-all [bug 1209903]
---
Created attachment 1012277
patch only to increase (not decrease) the hop-limit
---
- /* don't allow unreasonable small values */
+ /* don't allow unrea
Bugzilla
CVE-2015-2922 kernel: denial of service (DoS) attack against IPv6 network stacks due to improper handling of Router Advertisements.
bugzilla·2015-03-19·CVSS 3.3
CVE-2015-2922 [LOW] CVE-2015-2922 kernel: denial of service (DoS) attack against IPv6 network stacks due to improper handling of Router Advertisements.
CVE-2015-2922 kernel: denial of service (DoS) attack against IPv6 network stacks due to improper handling of Router Advertisements.
Linux kernel built with the IPv6 networking support(CONFIG_IPV6) is vulnerable to setting its 'hop_limit' too low, via the neighbour discovery protocol. It could result in thwarting the IPv6 functionality.
An unprivileged user on a local network could use this flaw to cause DoS to a remote system.
Upstream fix:
-> https://git.kernel.org/linus/6fd99094de2b83d1d4c8457f2c83483b2828e75a
Reference:
-> http://www.openwall.com/lists/oss-security/2015/04/04/2
Discussion:
Created attachment 1003851
linux-3.18-ipv6-hop_limit.patch
---
In the attachment there is a patch for the Linux kernel that fixes this issue.
Other suggested mitigations:
* Disallowing Router
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=6fd99094de2b83d1d4c8457f2c83483b2828e75ahttp://lists.fedoraproject.org/pipermail/package-announce/2015-April/155804.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-April/155854.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-April/155908.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00023.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-08/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00004.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1221.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1534.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1564.htmlhttp://www.debian.org/security/2015/dsa-3237http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.19.6http://www.openwall.com/lists/oss-security/2015/04/04/2http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.htmlhttp://www.securityfocus.com/bid/74315http://www.securitytracker.com/id/1032417https://bugzilla.redhat.com/show_bug.cgi?id=1203712https://github.com/torvalds/linux/commit/6fd99094de2b83d1d4c8457f2c83483b2828e75ahttp://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=6fd99094de2b83d1d4c8457f2c83483b2828e75ahttp://lists.fedoraproject.org/pipermail/package-announce/2015-April/155804.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-April/155854.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-April/155908.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00023.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-08/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00004.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1221.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1534.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1564.htmlhttp://www.debian.org/security/2015/dsa-3237http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.19.6http://www.openwall.com/lists/oss-security/2015/04/04/2http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.htmlhttp://www.securityfocus.com/bid/74315http://www.securitytracker.com/id/1032417https://bugzilla.redhat.com/show_bug.cgi?id=1203712https://github.com/torvalds/linux/commit/6fd99094de2b83d1d4c8457f2c83483b2828e75a
2015-05-27
Published