CVE-2015-8787
published 2016-02-08CVE-2015-8787: The nf_nat_redirect_ipv4 function in net/netfilter/nf_nat_redirect.c in the Linux kernel before 4.4 allows remote attackers to cause a denial of service (NULL…
PriorityP344critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
9.23%
94.8th percentile
The nf_nat_redirect_ipv4 function in net/netfilter/nf_nat_redirect.c in the Linux kernel before 4.4 allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by sending certain IPv4 packets to an incompletely configured interface, a related issue to CVE-2003-1604.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.3.5-1 (bookworm) | linux 4.3.5-1 (bookworm) |
| debian | linux | — | — |
| linux | linux_kernel | <= 2.5.75 | — |
| linux | linux_kernel | >= 0 < 4.3.5-1 | 4.3.5-1 |
| linux | linux_kernel | >= 0 < 4.3.5-1 | 4.3.5-1 |
| linux | linux_kernel | >= 0 < 4.3.5-1 | 4.3.5-1 |
| linux | linux_kernel | >= 0 < 4.3.5-1 | 4.3.5-1 |
| linux | linux_kernel | >= 3.19 < 4.1.31 | 4.1.31 |
| linux | linux_kernel | >= 4.2 < 4.4 | 4.4 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-959v-vp3p-vw6v: The nf_nat_redirect_ipv4 function in net/netfilter/nf_nat_redirect
ghsa_unreviewed·2022-05-13·CVSS 7.5
CVE-2015-8787 [HIGH] CWE-476 GHSA-959v-vp3p-vw6v: The nf_nat_redirect_ipv4 function in net/netfilter/nf_nat_redirect
The nf_nat_redirect_ipv4 function in net/netfilter/nf_nat_redirect.c in the Linux kernel before 4.4 allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by sending certain IPv4 packets to an incompletely configured interface, a related issue to CVE-2003-1604.
GHSA
GHSA-2xrh-r8pp-65w4: The redirect_target function in net/ipv4/netfilter/ipt_REDIRECT
ghsa_unreviewed·2022-04-29·CVSS 9.8
CVE-2003-1604 [CRITICAL] GHSA-2xrh-r8pp-65w4: The redirect_target function in net/ipv4/netfilter/ipt_REDIRECT
The redirect_target function in net/ipv4/netfilter/ipt_REDIRECT.c in the Linux kernel before 2.6.0 allows remote attackers to cause a denial of service (NULL pointer dereference and OOPS) by sending packets to an interface that has a 0.0.0.0 IP address, a related issue to CVE-2015-8787.
OSV
CVE-2015-8787: The nf_nat_redirect_ipv4 function in net/netfilter/nf_nat_redirect
osv·2016-02-08·CVSS 7.5
CVE-2015-8787 [HIGH] CVE-2015-8787: The nf_nat_redirect_ipv4 function in net/netfilter/nf_nat_redirect
The nf_nat_redirect_ipv4 function in net/netfilter/nf_nat_redirect.c in the Linux kernel before 4.4 allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by sending certain IPv4 packets to an incompletely configured interface, a related issue to CVE-2003-1604.
OSV
linux-lts-wily vulnerabilities
osv·2016-02-02·CVSS 5.3
CVE-2013-7446 [MEDIUM] linux-lts-wily vulnerabilities
linux-lts-wily vulnerabilities
It was discovered that a use-after-free vulnerability existed in the
AF_UNIX implementation in the Linux kernel. A local attacker could use
crafted epoll_ctl calls to cause a denial of service (system crash) or
expose sensitive information. (CVE-2013-7446)
It was discovered that the KVM implementation in the Linux kernel did not
properly restore the values of the Programmable Interrupt Timer (PIT). A
user-assisted attacker in a KVM guest could cause a denial of service in
the host (system crash). (CVE-2015-7513)
It was discovered that the Linux kernel keyring subsystem contained a race
between read and revoke operations. A local attacker could use this to
cause a denial of service (system crash). (CVE-2015-7550)
Sasha Levin discovered that the Reliable Da
OSV
linux-lts-vivid vulnerabilities
osv·2016-02-02·CVSS 5.3
CVE-2013-7446 [MEDIUM] linux-lts-vivid vulnerabilities
linux-lts-vivid vulnerabilities
It was discovered that a use-after-free vulnerability existed in the
AF_UNIX implementation in the Linux kernel. A local attacker could use
crafted epoll_ctl calls to cause a denial of service (system crash) or
expose sensitive information. (CVE-2013-7446)
It was discovered that the KVM implementation in the Linux kernel did not
properly restore the values of the Programmable Interrupt Timer (PIT). A
user-assisted attacker in a KVM guest could cause a denial of service in
the host (system crash). (CVE-2015-7513)
Sasha Levin discovered that the Reliable Datagram Sockets (RDS)
implementation in the Linux kernel had a race condition when checking
whether a socket was bound or not. A local attacker could use this to cause
a denial of service (system crash). (
Ubuntu
Linux kernel (Vivid HWE) vulnerabilities
vendor_ubuntu·2016-02-02·CVSS 5.3
CVE-2013-7446 [MEDIUM] Linux kernel (Vivid HWE) vulnerabilities
Title: Linux kernel (Vivid HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that a use-after-free vulnerability existed in the
AF_UNIX implementation in the Linux kernel. A local attacker could use
crafted epoll_ctl calls to cause a denial of service (system crash) or
expose sensitive information. (CVE-2013-7446)
It was discovered that the KVM implementation in the Linux kernel did not
properly restore the values of the Programmable Interrupt Timer (PIT). A
user-assisted attacker in a KVM guest could cause a denial of service in
the host (system crash). (CVE-2015-7513)
Sasha Levin discovered that the Reliable Datagram Sockets (RDS)
implementation in the Linux kernel had a race condition when checking
whether a socket was bound or not. A
Ubuntu
Linux kernel (Wily HWE) vulnerabilities
vendor_ubuntu·2016-02-02·CVSS 5.3
CVE-2013-7446 [MEDIUM] Linux kernel (Wily HWE) vulnerabilities
Title: Linux kernel (Wily HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that a use-after-free vulnerability existed in the
AF_UNIX implementation in the Linux kernel. A local attacker could use
crafted epoll_ctl calls to cause a denial of service (system crash) or
expose sensitive information. (CVE-2013-7446)
It was discovered that the KVM implementation in the Linux kernel did not
properly restore the values of the Programmable Interrupt Timer (PIT). A
user-assisted attacker in a KVM guest could cause a denial of service in
the host (system crash). (CVE-2015-7513)
It was discovered that the Linux kernel keyring subsystem contained a race
between read and revoke operations. A local attacker could use this to
cause a denial of service
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2016-02-02·CVSS 5.3
CVE-2013-7446 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that a use-after-free vulnerability existed in the
AF_UNIX implementation in the Linux kernel. A local attacker could use
crafted epoll_ctl calls to cause a denial of service (system crash) or
expose sensitive information. (CVE-2013-7446)
It was discovered that the KVM implementation in the Linux kernel did not
properly restore the values of the Programmable Interrupt Timer (PIT). A
user-assisted attacker in a KVM guest could cause a denial of service in
the host (system crash). (CVE-2015-7513)
Sasha Levin discovered that the Reliable Datagram Sockets (RDS)
implementation in the Linux kernel had a race condition when checking
whether a socket was bound or not. A local attack
Ubuntu
Linux kernel (Raspberry Pi 2) vulnerabilities
vendor_ubuntu·2016-02-02·CVSS 5.3
CVE-2013-7446 [MEDIUM] Linux kernel (Raspberry Pi 2) vulnerabilities
Title: Linux kernel (Raspberry Pi 2) vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that a use-after-free vulnerability existed in the
AF_UNIX implementation in the Linux kernel. A local attacker could use
crafted epoll_ctl calls to cause a denial of service (system crash) or
expose sensitive information. (CVE-2013-7446)
It was discovered that the KVM implementation in the Linux kernel did not
properly restore the values of the Programmable Interrupt Timer (PIT). A
user-assisted attacker in a KVM guest could cause a denial of service in
the host (system crash). (CVE-2015-7513)
It was discovered that the Linux kernel keyring subsystem contained a race
between read and revoke operations. A local attacker could use this to
cause a denial of se
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2016-02-02·CVSS 5.3
CVE-2013-7446 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that a use-after-free vulnerability existed in the
AF_UNIX implementation in the Linux kernel. A local attacker could use
crafted epoll_ctl calls to cause a denial of service (system crash) or
expose sensitive information. (CVE-2013-7446)
It was discovered that the KVM implementation in the Linux kernel did not
properly restore the values of the Programmable Interrupt Timer (PIT). A
user-assisted attacker in a KVM guest could cause a denial of service in
the host (system crash). (CVE-2015-7513)
It was discovered that the Linux kernel keyring subsystem contained a race
between read and revoke operations. A local attacker could use this to
cause a denial of service (system cra
Red Hat
kernel: Missing NULL pointer check in nf_nat_redirect_ipv4
vendor_redhat·2015-12-02·CVSS 7.5
CVE-2015-8787 [HIGH] CWE-476 kernel: Missing NULL pointer check in nf_nat_redirect_ipv4
kernel: Missing NULL pointer check in nf_nat_redirect_ipv4
The nf_nat_redirect_ipv4 function in net/netfilter/nf_nat_redirect.c in the Linux kernel before 4.4 allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by sending certain IPv4 packets to an incompletely configured interface, a related issue to CVE-2003-1604.
A NULL-pointer dereference vulnerability was found in the Linux kernel's TCP stack, in net/netfilter/nf_nat_redirect.c in the nf_nat_redirect_ipv4() function. A remote, unauthenticated user could exploit this flaw to create a system crash (denial of service).
Statement: This issue does not affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 5, 6, 7 and MRG-2 as the co
Debian
CVE-2015-8787: linux - The nf_nat_redirect_ipv4 function in net/netfilter/nf_nat_redirect.c in the Linu...
vendor_debian·2015·CVSS 7.5
CVE-2015-8787 [HIGH] CVE-2015-8787: linux - The nf_nat_redirect_ipv4 function in net/netfilter/nf_nat_redirect.c in the Linu...
The nf_nat_redirect_ipv4 function in net/netfilter/nf_nat_redirect.c in the Linux kernel before 4.4 allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by sending certain IPv4 packets to an incompletely configured interface, a related issue to CVE-2003-1604.
Scope: local
bookworm: resolved (fixed in 4.3.5-1)
bullseye: resolved (fixed in 4.3.5-1)
forky: resolved (fixed in 4.3.5-1)
sid: resolved (fixed in 4.3.5-1)
trixie: resolved (fixed in 4.3.5-1)
Red Hat
kernel: Missing NULL pointer check in nf_nat_redirect_ipv4
vendor_redhat·2003-10-20·CVSS 7.5
CVE-2003-1604 [HIGH] CWE-476 kernel: Missing NULL pointer check in nf_nat_redirect_ipv4
kernel: Missing NULL pointer check in nf_nat_redirect_ipv4
The redirect_target function in net/ipv4/netfilter/ipt_REDIRECT.c in the Linux kernel before 2.6.0 allows remote attackers to cause a denial of service (NULL pointer dereference and OOPS) by sending packets to an interface that has a 0.0.0.0 IP address, a related issue to CVE-2015-8787.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: realtime-kernel (Red Hat Enterprise MRG 2) - Not affected
Debian
CVE-2003-1604: linux - The redirect_target function in net/ipv4/netfilter/ipt_REDIRECT.c in the Linux k...
vendor_debian·2003·CVSS 7.5
CVE-2003-1604 [HIGH] CVE-2003-1604: linux - The redirect_target function in net/ipv4/netfilter/ipt_REDIRECT.c in the Linux k...
The redirect_target function in net/ipv4/netfilter/ipt_REDIRECT.c in the Linux kernel before 2.6.0 allows remote attackers to cause a denial of service (NULL pointer dereference and OOPS) by sending packets to an interface that has a 0.0.0.0 IP address, a related issue to CVE-2015-8787.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-8787 kernel: Missing NULL pointer check in nf_nat_redirect_ipv4 [fedora-all]
bugzilla·2016-01-21·CVSS 9.8
CVE-2015-8787 [CRITICAL] CVE-2015-8787 kernel: Missing NULL pointer check in nf_nat_redirect_ipv4 [fedora-all]
CVE-2015-8787 kernel: Missing NULL pointer check in nf_nat_redirect_ipv4 [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported vers
Bugzilla
CVE-2015-8787 kernel: Missing NULL pointer check in nf_nat_redirect_ipv4
bugzilla·2016-01-21·CVSS 9.8
CVE-2015-8787 [CRITICAL] CVE-2015-8787 kernel: Missing NULL pointer check in nf_nat_redirect_ipv4
CVE-2015-8787 kernel: Missing NULL pointer check in nf_nat_redirect_ipv4
Kernel NULL pointer dereference vulnerability was found in netfilter/nf_nat_redirect.c in nf_nat_redirect_ipv4 function introduced by commit 8b13eddfdf04cbfa561725cfc42d6868fe896f56 ("netfilter: refactor NAT redirect IPv4 to use it from nf_tables").
Vulnerable code:
unsigned int
nf_nat_redirect_ipv4(struct sk_buff *skb,
...
{
...
rcu_read_lock();
indev = __in_dev_get_rcu(skb->dev);
if (indev != NULL) {
ifa = indev->ifa_list;
newdst = ifa->ifa_local; Patch and crash report:
>
> https://lkml.org/lkml/2015/12/2/618
This is commit 94f9cd81436c85d8c3a318ba92e236ede73752fc in Linus' tree. It was included with the 4.4-rc1 release.
---
an upstream commit introduced the flaw:
http://git.kernel.org/cgit/linux/kernel/git/t
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=94f9cd81436c85d8c3a318ba92e236ede73752fchttp://lists.fedoraproject.org/pipermail/package-announce/2016-February/176464.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-February/176484.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00015.htmlhttp://www.openwall.com/lists/oss-security/2016/01/27/6http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinoct2016-3090547.htmlhttp://www.ubuntu.com/usn/USN-2889-1http://www.ubuntu.com/usn/USN-2889-2http://www.ubuntu.com/usn/USN-2890-1http://www.ubuntu.com/usn/USN-2890-2http://www.ubuntu.com/usn/USN-2890-3https://bugzilla.redhat.com/show_bug.cgi?id=1300731https://github.com/torvalds/linux/commit/94f9cd81436c85d8c3a318ba92e236ede73752fchttp://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=94f9cd81436c85d8c3a318ba92e236ede73752fchttp://lists.fedoraproject.org/pipermail/package-announce/2016-February/176464.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-February/176484.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00015.htmlhttp://www.openwall.com/lists/oss-security/2016/01/27/6http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinoct2016-3090547.htmlhttp://www.ubuntu.com/usn/USN-2889-1http://www.ubuntu.com/usn/USN-2889-2http://www.ubuntu.com/usn/USN-2890-1http://www.ubuntu.com/usn/USN-2890-2http://www.ubuntu.com/usn/USN-2890-3https://bugzilla.redhat.com/show_bug.cgi?id=1300731https://github.com/torvalds/linux/commit/94f9cd81436c85d8c3a318ba92e236ede73752fc
2016-02-08
Published