CVE-2021-46955
published 2024-02-27CVE-2021-46955: In the Linux kernel, the following vulnerability has been resolved: openvswitch: fix stack OOB read while fragmenting IPv4 packets running openvswitch on…
PriorityP431high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.25%
17.0th percentile
In the Linux kernel, the following vulnerability has been resolved:
openvswitch: fix stack OOB read while fragmenting IPv4 packets
running openvswitch on kernels built with KASAN, it's possible to see the
following splat while testing fragmentation of IPv4 packets:
BUG: KASAN: stack-out-of-bounds in ip_do_fragment+0x1b03/0x1f60
Read of size 1 at addr ffff888112fc713c by task handler2/1367
CPU: 0 PID: 1367 Comm: handler2 Not tainted 5.12.0-rc6+ #418
Hardware name: Red Hat KVM, BIOS 1.11.1-4.module+el8.1.0+4066+0f1aadab 04/01/2014
Call Trace:
dump_stack+0x92/0xc1
print_address_description.constprop.7+0x1a/0x150
kasan_report.cold.13+0x7f/0x111
ip_do_fragment+0x1b03/0x1f60
ovs_fragment+0x5bf/0x840 [openvswitch]
do_execute_actions+0x1bd5/0x2400 [openvswitch]
ovs_execute_actions+0xc8/0x3d0 [openvswitch]
ovs_packet_cmd_execute+0xa39/0x1150 [openvswitch]
genl_family_rcv_msg_doit.isra.15+0x227/0x2d0
genl_rcv_msg+0x287/0x490
netlink_rcv_skb+0x120/0x380
genl_rcv+0x24/0x40
netlink_unicast+0x439/0x630
netlink_sendmsg+0x719/0xbf0
sock_sendmsg+0xe2/0x110
____sys_sendmsg+0x5ba/0x890
___sys_sendmsg+0xe9/0x160
__sys_sendmsg+0xd3/0x170
do_syscall_64+0x33/0x40
entry_SYSCALL_64_after_hwframe+0x44/0xae
RIP: 0033:0x7f957079db07
Code: c3 66 90 41 54 41 89 d4 55 48 89 f5 53 89 fb 48 83 ec 10 e8 eb ec ff ff 44 89 e2 48 89 ee 89 df 41 89 c0 b8 2e 00 00 00 0f 05 3d 00 f0 ff ff 77 35 44 89 c7 48 89 44 24 08 e8 24 ed ff ff 48
RSP: 002b:00007f956ce35a50 EFLAGS: 00000293 ORIG_RAX: 000000000000002e
RAX: ffffffffffffffda RBX: 0000000000000019 RCX: 00007f957079db07
RDX: 0000000000000000 RSI: 00007f956ce35ae0 RDI: 0000000000000019
RBP: 00007f956ce35ae0 R08: 0000000000000000 R09: 00007f9558006730
R10: 0000000000000000 R11: 0000000000000293 R12: 0000000000000000
R13: 00007f956ce37308 R14: 00007f956ce35f80 R15: 00007f956ce35ae0
The buggy address belongs to the page:
page:00000000af2a1d93 refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x112fc7
flags: 0x17ffffc0000000()
raw: 0017ffffc000
Affected
29 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.10.38-1 (bookworm) | linux 5.10.38-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | >= 119bbaa6795a4f4aed46994cc7d9ab01989c87e3 < b1d7280f9ba1bfdbc3af5bdb82e51f014854f26f | b1d7280f9ba1bfdbc3af5bdb82e51f014854f26f |
| linux | linux | >= 3.16.57 < 3.17 | 3.17 |
| linux | linux | >= 4.14.45 < 4.14.233 | 4.14.233 |
| linux | linux | >= 4.4.134 < 4.4.269 | 4.4.269 |
| linux | linux | >= 4.9.104 < 4.9.269 | 4.9.269 |
| linux | linux | >= 8387fbac8e18e26a60559adc63e0b7067303b0a4 < 5a52fa8ad45b5a593ed416adf326538638454ff1 | 5a52fa8ad45b5a593ed416adf326538638454ff1 |
| linux | linux | >= d52e5a7e7ca49457dd31fc8b42fb7c0d58a31221 < df9e900de24637be41879e2c50afb713ec4e8b2e | df9e900de24637be41879e2c50afb713ec4e8b2e |
| linux | linux | >= d52e5a7e7ca49457dd31fc8b42fb7c0d58a31221 < 490ad0a2390442d0a7b8c00972a83dbb09cab142 | 490ad0a2390442d0a7b8c00972a83dbb09cab142 |
| linux | linux | >= d52e5a7e7ca49457dd31fc8b42fb7c0d58a31221 < a1478374b0bda89b4277a8afd39208271faad4be | a1478374b0bda89b4277a8afd39208271faad4be |
| linux | linux | >= d52e5a7e7ca49457dd31fc8b42fb7c0d58a31221 < d841d3cf5297fde4ce6a41ff35451d0e82917f3e | d841d3cf5297fde4ce6a41ff35451d0e82917f3e |
| linux | linux | >= d52e5a7e7ca49457dd31fc8b42fb7c0d58a31221 < b3502b04e84ac5349be95fc033c17bd701d2787a | b3502b04e84ac5349be95fc033c17bd701d2787a |
| linux | linux | >= d52e5a7e7ca49457dd31fc8b42fb7c0d58a31221 < 7c0ea5930c1c211931819d83cfb157bff1539a4c | 7c0ea5930c1c211931819d83cfb157bff1539a4c |
| linux | linux | >= d543907a4730400f5c5b684c57cb5bbbfd6136ab < 23e17ec1a5eb53fe39cc34fa5592686d5acd0dac | 23e17ec1a5eb53fe39cc34fa5592686d5acd0dac |
| linux | linux_kernel | >= 0 < 5.10.38-1 | 5.10.38-1 |
| linux | linux_kernel | >= 0 < 5.10.38-1 | 5.10.38-1 |
| linux | linux_kernel | >= 0 < 5.10.38-1 | 5.10.38-1 |
| linux | linux_kernel | >= 0 < 5.10.38-1 | 5.10.38-1 |
| linux | linux_kernel | >= 0 < 4.4.0-253.287 | 4.4.0-253.287 |
| linux | linux_kernel | >= 4.14.45 < 4.14.233 | 4.14.233 |
| linux | linux_kernel | >= 4.16 < 4.19.191 | 4.19.191 |
| linux | linux_kernel | >= 4.20 < 5.4.118 | 5.4.118 |
| linux | linux_kernel | >= 4.4.134 < 4.4.269 | 4.4.269 |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
vendor_ubuntu7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2024-04-19·CVSS 7.0
CVE-2023-1382 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that a race condition existed in the instruction emulator
of the Linux kernel on Arm 64-bit systems. A local attacker could use this
to cause a denial of service (system crash). (CVE-2022-20422)
Wei Chen discovered that a race condition existed in the TIPC protocol
implementation in the Linux kernel, leading to a null pointer dereference
vulnerability. A local attacker could use this to cause a denial of service
(system crash). (CVE-2023-1382)
Jose Oliveira and Rodrigo Branco discovered that the Spectre Variant 2
mitigations with prctl syscall were insufficient in some situations. A
local attacker could possibly use this to expose sensitive information.
(CVE-2023-1998)
Red Hat
kernel: openvswitch: fix stack OOB read while fragmenting IPv4 packets
vendor_redhat·2024-02-27·CVSS 7.1
CVE-2021-46955 [HIGH] CWE-125 kernel: openvswitch: fix stack OOB read while fragmenting IPv4 packets
kernel: openvswitch: fix stack OOB read while fragmenting IPv4 packets
In the Linux kernel, the following vulnerability has been resolved:
openvswitch: fix stack OOB read while fragmenting IPv4 packets
running openvswitch on kernels built with KASAN, it's possible to see the
following splat while testing fragmentation of IPv4 packets:
BUG: KASAN: stack-out-of-bounds in ip_do_fragment+0x1b03/0x1f60
Read of size 1 at addr ffff888112fc713c by task handler2/1367
CPU: 0 PID: 1367 Comm: handler2 Not tainted 5.12.0-rc6+ #418
Hardware name: Red Hat KVM, BIOS 1.11.1-4.module+el8.1.0+4066+0f1aadab 04/01/2014
Call Trace:
dump_stack+0x92/0xc1
print_address_description.constprop.7+0x1a/0x150
kasan_report.cold.13+0x7f/0x111
ip_do_fragment+0x1b03/0x1f60
ovs_fragment+0x5bf/0x840 [openvswitch]
do_execute_
Debian
CVE-2021-46955: linux - In the Linux kernel, the following vulnerability has been resolved: openvswitch...
vendor_debian·2021·CVSS 7.1
CVE-2021-46955 [HIGH] CVE-2021-46955: linux - In the Linux kernel, the following vulnerability has been resolved: openvswitch...
In the Linux kernel, the following vulnerability has been resolved: openvswitch: fix stack OOB read while fragmenting IPv4 packets running openvswitch on kernels built with KASAN, it's possible to see the following splat while testing fragmentation of IPv4 packets: BUG: KASAN: stack-out-of-bounds in ip_do_fragment+0x1b03/0x1f60 Read of size 1 at addr ffff888112fc713c by task handler2/1367 CPU: 0 PID: 1367 Comm: handler2 Not tainted 5.12.0-rc6+ #418 Hardware name: Red Hat KVM, BIOS 1.11.1-4.module+el8.1.0+4066+0f1aadab 04/01/2014 Call Trace: dump_stack+0x92/0xc1 print_address_description.constprop.7+0x1a/0x150 kasan_report.cold.13+0x7f/0x111 ip_do_fragment+0x1b03/0x1f60 ovs_fragment+0x5bf/0x840 [openvswitch] do_execute_actions+0x1bd5/0x2400 [openvswitch] ovs_execute_actions+0xc8/0x3d0 [open
OSV
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities
osv·2024-04-19·CVSS 7.0
CVE-2022-20422 [HIGH] linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities
It was discovered that a race condition existed in the instruction emulator
of the Linux kernel on Arm 64-bit systems. A local attacker could use this
to cause a denial of service (system crash). (CVE-2022-20422)
Wei Chen discovered that a race condition existed in the TIPC protocol
implementation in the Linux kernel, leading to a null pointer dereference
vulnerability. A local attacker could use this to cause a denial of service
(system crash). (CVE-2023-1382)
Jose Oliveira and Rodrigo Branco discovered that the Spectre Variant 2
mitigations with prctl syscall were insufficient in some situations. A
local attacker could possibly use this to expose sensitive information.
(CVE-2023-1998)
Daniele Antonioli discovered that the
OSV
CVE-2021-46955: In the Linux kernel, the following vulnerability has been resolved: openvswitch: fix stack OOB read while fragmenting IPv4 packets running openvswitch
osv·2024-02-27·CVSS 7.1
CVE-2021-46955 [HIGH] CVE-2021-46955: In the Linux kernel, the following vulnerability has been resolved: openvswitch: fix stack OOB read while fragmenting IPv4 packets running openvswitch
In the Linux kernel, the following vulnerability has been resolved: openvswitch: fix stack OOB read while fragmenting IPv4 packets running openvswitch on kernels built with KASAN, it's possible to see the following splat while testing fragmentation of IPv4 packets: BUG: KASAN: stack-out-of-bounds in ip_do_fragment+0x1b03/0x1f60 Read of size 1 at addr ffff888112fc713c by task handler2/1367 CPU: 0 PID: 1367 Comm: handler2 Not tainted 5.12.0-rc6+ #418 Hardware name: Red Hat KVM, BIOS 1.11.1-4.module+el8.1.0+4066+0f1aadab 04/01/2014 Call Trace: dump_stack+0x92/0xc1 print_address_description.constprop.7+0x1a/0x150 kasan_report.cold.13+0x7f/0x111 ip_do_fragment+0x1b03/0x1f60 ovs_fragment+0x5bf/0x840 [openvswitch] do_execute_actions+0x1bd5/0x2400 [openvswitch] ovs_execute_actions+0xc8/0x3d0 [open
GHSA
GHSA-6mwq-mrw3-3m6c: In the Linux kernel, the following vulnerability has been resolved:
openvswitch: fix stack OOB read while fragmenting IPv4 packets
running openvswit
ghsa_unreviewed·2024-02-27
CVE-2021-46955 [HIGH] CWE-125 GHSA-6mwq-mrw3-3m6c: In the Linux kernel, the following vulnerability has been resolved:
openvswitch: fix stack OOB read while fragmenting IPv4 packets
running openvswit
In the Linux kernel, the following vulnerability has been resolved:
openvswitch: fix stack OOB read while fragmenting IPv4 packets
running openvswitch on kernels built with KASAN, it's possible to see the
following splat while testing fragmentation of IPv4 packets:
BUG: KASAN: stack-out-of-bounds in ip_do_fragment+0x1b03/0x1f60
Read of size 1 at addr ffff888112fc713c by task handler2/1367
CPU: 0 PID: 1367 Comm: handler2 Not tainted 5.12.0-rc6+ #418
Hardware name: Red Hat KVM, BIOS 1.11.1-4.module+el8.1.0+4066+0f1aadab 04/01/2014
Call Trace:
dump_stack+0x92/0xc1
print_address_description.constprop.7+0x1a/0x150
kasan_report.cold.13+0x7f/0x111
ip_do_fragment+0x1b03/0x1f60
ovs_fragment+0x5bf/0x840 [openvswitch]
do_execute_actions+0x1bd5/0x2400 [openvswitch]
ovs_execute_actions+0xc8/0x3d0 [
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/23e17ec1a5eb53fe39cc34fa5592686d5acd0dachttps://git.kernel.org/stable/c/490ad0a2390442d0a7b8c00972a83dbb09cab142https://git.kernel.org/stable/c/5a52fa8ad45b5a593ed416adf326538638454ff1https://git.kernel.org/stable/c/7c0ea5930c1c211931819d83cfb157bff1539a4chttps://git.kernel.org/stable/c/a1478374b0bda89b4277a8afd39208271faad4behttps://git.kernel.org/stable/c/b1d7280f9ba1bfdbc3af5bdb82e51f014854f26fhttps://git.kernel.org/stable/c/b3502b04e84ac5349be95fc033c17bd701d2787ahttps://git.kernel.org/stable/c/d841d3cf5297fde4ce6a41ff35451d0e82917f3ehttps://git.kernel.org/stable/c/df9e900de24637be41879e2c50afb713ec4e8b2ehttps://git.kernel.org/stable/c/23e17ec1a5eb53fe39cc34fa5592686d5acd0dachttps://git.kernel.org/stable/c/490ad0a2390442d0a7b8c00972a83dbb09cab142https://git.kernel.org/stable/c/5a52fa8ad45b5a593ed416adf326538638454ff1https://git.kernel.org/stable/c/7c0ea5930c1c211931819d83cfb157bff1539a4chttps://git.kernel.org/stable/c/a1478374b0bda89b4277a8afd39208271faad4behttps://git.kernel.org/stable/c/b1d7280f9ba1bfdbc3af5bdb82e51f014854f26fhttps://git.kernel.org/stable/c/b3502b04e84ac5349be95fc033c17bd701d2787ahttps://git.kernel.org/stable/c/d841d3cf5297fde4ce6a41ff35451d0e82917f3ehttps://git.kernel.org/stable/c/df9e900de24637be41879e2c50afb713ec4e8b2e
2024-02-27
Published