CVE-2016-10142
published 2017-01-14CVE-2016-10142: An issue was discovered in the IPv6 protocol specification, related to ICMP Packet Too Big (PTB) messages. (The scope of this CVE is all affected IPv6…
PriorityP345high8.6CVSS 3.0
AVNACLPRNUINSCCNINAH
EPSS
2.75%
84.5th percentile
An issue was discovered in the IPv6 protocol specification, related to ICMP Packet Too Big (PTB) messages. (The scope of this CVE is all affected IPv6 implementations from all vendors.) The security implications of IP fragmentation have been discussed at length in [RFC6274] and [RFC7739]. An attacker can leverage the generation of IPv6 atomic fragments to trigger the use of fragmentation in an arbitrary IPv6 flow (in scenarios in which actual fragmentation of packets is not needed) and can subsequently perform any type of fragmentation-based attack against legacy IPv6 nodes that do not implement [RFC6946]. That is, employing fragmentation where not actually needed allows for fragmentation-based attack vectors to be employed, unnecessarily. We note that, unfortunately, even nodes that already implement [RFC6946] can be subject to DoS attacks as a result of the generation of IPv6 atomic fragments. Let us assume that Host A is communicating with Host B and that, as a result of the widespread dropping of IPv6 packets that contain extension headers (including fragmentation) [RFC7872], some intermediate node filters fragments between Host B and Host A. If an attacker sends a forged ICMPv6 PTB error message to Host B, reporting an MTU smaller than 1280, this will trigger the generation of IPv6 atomic fragments from that moment on (as required by [RFC2460]). When Host B starts sending IPv6 atomic fragments (in response to the received ICMPv6 PTB error message), these packets will be dropped, since we previously noted that IPv6 packets with extension headers were being dropped between Host B and Host A. Thus, this situation will result in a DoS scenario. Another possible scenario is that in which two BGP peers are employing IPv6 transport and they implement Access Control Lists (ACLs) to drop IPv6 fragments (to avoid control-plane attacks). If the aforementioned BGP peers drop IPv6 fragments but still honor received ICMPv6 PTB error messages, an attacker could easily attack
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux_kernel | >= 0 < 3.13.0-51.84 | 3.13.0-51.84 |
CVSS provenance
nvdv3.08.6HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv8.6HIGH
vendor_redhat8.6HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4jqq-7wwq-485f: An issue was discovered in the IPv6 protocol specification, related to ICMP Packet Too Big (PTB) messages
ghsa_unreviewed·2022-05-14
CVE-2016-10142 [HIGH] GHSA-4jqq-7wwq-485f: An issue was discovered in the IPv6 protocol specification, related to ICMP Packet Too Big (PTB) messages
An issue was discovered in the IPv6 protocol specification, related to ICMP Packet Too Big (PTB) messages. (The scope of this CVE is all affected IPv6 implementations from all vendors.) The security implications of IP fragmentation have been discussed at length in [RFC6274] and [RFC7739]. An attacker can leverage the generation of IPv6 atomic fragments to trigger the use of fragmentation in an arbitrary IPv6 flow (in scenarios in which actual fragmentation of packets is not needed) and can subsequently perform any type of fragmentation-based attack against legacy IPv6 nodes that do not implement [RFC6946]. That is, employing fragmentation where not actually needed allows for fragmentation-based attack vectors to be employed, unnecessarily. We note that, unfortunately, even nodes that alrea
OSV
CVE-2016-10142: An issue was discovered in the IPv6 protocol specification, related to ICMP Packet Too Big (PTB) messages
osv·2017-01-14·CVSS 8.6
CVE-2016-10142 [HIGH] CVE-2016-10142: An issue was discovered in the IPv6 protocol specification, related to ICMP Packet Too Big (PTB) messages
An issue was discovered in the IPv6 protocol specification, related to ICMP Packet Too Big (PTB) messages. (The scope of this CVE is all affected IPv6 implementations from all vendors.) The security implications of IP fragmentation have been discussed at length in [RFC6274] and [RFC7739]. An attacker can leverage the generation of IPv6 atomic fragments to trigger the use of fragmentation in an arbitrary IPv6 flow (in scenarios in which actual fragmentation of packets is not needed) and can subsequently perform any type of fragmentation-based attack against legacy IPv6 nodes that do not implement [RFC6946]. That is, employing fragmentation where not actually needed allows for fragmentation-based attack vectors to be employed, unnecessarily. We note that, unfortunately, even nodes that alrea
Red Hat
kernel - IPV6 fragmentation flaw
vendor_redhat·2017-01-24·CVSS 8.6
CVE-2016-10142 [HIGH] CWE-406 kernel - IPV6 fragmentation flaw
kernel - IPV6 fragmentation flaw
An issue was discovered in the IPv6 protocol specification, related to ICMP Packet Too Big (PTB) messages. (The scope of this CVE is all affected IPv6 implementations from all vendors.) The security implications of IP fragmentation have been discussed at length in [RFC6274] and [RFC7739]. An attacker can leverage the generation of IPv6 atomic fragments to trigger the use of fragmentation in an arbitrary IPv6 flow (in scenarios in which actual fragmentation of packets is not needed) and can subsequently perform any type of fragmentation-based attack against legacy IPv6 nodes that do not implement [RFC6946]. That is, employing fragmentation where not actually needed allows for fragmentation-based attack vectors to be employed, unnecessarily. We note that, un
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-10142 - IPV6 fragmentation flaw
bugzilla·2017-01-24·CVSS 8.6
CVE-2016-10142 [HIGH] CVE-2016-10142 - IPV6 fragmentation flaw
CVE-2016-10142 - IPV6 fragmentation flaw
An issue was discovered in the IPv6 protocol specification, related to ICMP Packet Too Big (PTB) messages. (The scope of this CVE is all affected IPv6 implementations from all vendors.) The security implications of IP fragmentation have been discussed at length in [RFC6274] and [RFC7739]. An attacker can leverage the generation of IPv6 atomic fragments to trigger the use of fragmentation in an arbitrary IPv6 flow (in scenarios in which actual fragmentation of packets is not needed) and can subsequently perform any type of fragmentation-based attack against legacy IPv6 nodes that do not implement [RFC6946]. That is, employing fragmentation where not actually needed allows for fragmentation-based attack vectors to be employed, unnecessarily.
We note
Bugzilla
CVE-2016-10142 kernel: kernel - IPV6 fragmentation flaw [fedora-all]
bugzilla·2017-01-24·CVSS 8.6
CVE-2016-10142 [HIGH] CVE-2016-10142 kernel: kernel - IPV6 fragmentation flaw [fedora-all]
CVE-2016-10142 kernel: kernel - IPV6 fragmentation flaw [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. W
Bugzilla
CVE-2016-10142 kernel - IPV6 fragmentation flaw
bugzilla·2017-01-24·CVSS 8.6
CVE-2016-10142 [HIGH] CVE-2016-10142 kernel - IPV6 fragmentation flaw
CVE-2016-10142 kernel - IPV6 fragmentation flaw
An issue was discovered in the IPv6 protocol specification, related to ICMP Packet Too Big (PTB) messages. (The scope of this CVE is all affected IPv6 implementations from all vendors.) The security implications of IP fragmentation have been discussed at length in [RFC6274] and [RFC7739]. An attacker can leverage the generation of IPv6 atomic fragments to trigger the use of fragmentation in an arbitrary IPv6 flow (in scenarios in which actual fragmentation of packets is not needed) and can subsequently perform any type of fragmentation-based attack against legacy IPv6 nodes that do not implement [RFC6946]. That is, employing fragmentation where not actually needed allows for fragmentation-based attack vectors to be employed, unnecessarily.
http://rhn.redhat.com/errata/RHSA-2017-0817.htmlhttp://www.securityfocus.com/bid/95797http://www.securitytracker.com/id/1038256https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA43730https://support.f5.com/csp/article/K57211290?utm_source=f5support&%3Butm_medium=RSShttps://tools.ietf.org/html/draft-ietf-6man-deprecate-atomfrag-generation-08https://tools.ietf.org/html/rfc8021http://rhn.redhat.com/errata/RHSA-2017-0817.htmlhttp://www.securityfocus.com/bid/95797http://www.securitytracker.com/id/1038256https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA43730https://support.f5.com/csp/article/K57211290?utm_source=f5support&%3Butm_medium=RSShttps://tools.ietf.org/html/draft-ietf-6man-deprecate-atomfrag-generation-08https://tools.ietf.org/html/rfc8021
2017-01-14
Published