CVE-2021-47515
published 2024-05-24CVE-2021-47515: In the Linux kernel, the following vulnerability has been resolved: seg6: fix the iif in the IPv6 socket control block When an IPv4 packet is received, the…
PriorityP422medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.75%
51.3th percentile
In the Linux kernel, the following vulnerability has been resolved:
seg6: fix the iif in the IPv6 socket control block
When an IPv4 packet is received, the ip_rcv_core(...) sets the receiving
interface index into the IPv4 socket control block (v5.16-rc4,
net/ipv4/ip_input.c line 510):
IPCB(skb)->iif = skb->skb_iif;
If that IPv4 packet is meant to be encapsulated in an outer IPv6+SRH
header, the seg6_do_srh_encap(...) performs the required encapsulation.
In this case, the seg6_do_srh_encap function clears the IPv6 socket control
block (v5.16-rc4 net/ipv6/seg6_iptunnel.c line 163):
memset(IP6CB(skb), 0, sizeof(*IP6CB(skb)));
The memset(...) was introduced in commit ef489749aae5 ("ipv6: sr: clear
IP6CB(skb) on SRH ip4ip6 encapsulation") a long time ago (2019-01-29).
Since the IPv6 socket control block and the IPv4 socket control block share
the same memory area (skb->cb), the receiving interface index info is lost
(IP6CB(skb)->iif is set to zero).
As a side effect, that condition triggers a NULL pointer dereference if
commit 0857d6f8c759 ("ipv6: When forwarding count rx stats on the orig
netdev") is applied.
To fix that issue, we set the IP6CB(skb)->iif with the index of the
receiving interface once again.
Affected
30 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.15.15-1 (bookworm) | linux 5.15.15-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | >= 2f704348c93ff8119e642dae6a72327f90b82810 < 6431e71093f3da586a00c6d931481ffb0dc2db0e | 6431e71093f3da586a00c6d931481ffb0dc2db0e |
| linux | linux | >= 4.14.98 < 4.14.258 | 4.14.258 |
| linux | linux | >= 4.19.20 < 4.19.221 | 4.19.221 |
| linux | linux | >= 4.20.7 < 4.21 | 4.21 |
| linux | linux | >= c630ec8bdadae9d557b1ceb9d6c06e149108a0d4 < b16d412e5f79734033df04e97d7ea2f50a8e9fe3 | b16d412e5f79734033df04e97d7ea2f50a8e9fe3 |
| linux | linux | >= ef489749aae508e6f17886775c075f12ff919fb1 < ef8804e47c0a44ae106ead1740408af5ea6c6ee9 | ef8804e47c0a44ae106ead1740408af5ea6c6ee9 |
| linux | linux | >= ef489749aae508e6f17886775c075f12ff919fb1 < 666521b3852d2b2f52d570f9122b1e4b50d96831 | 666521b3852d2b2f52d570f9122b1e4b50d96831 |
| linux | linux | >= ef489749aae508e6f17886775c075f12ff919fb1 < 98adb2bbfa407c9290bda299d4c6f7a1c4ebd5e1 | 98adb2bbfa407c9290bda299d4c6f7a1c4ebd5e1 |
| linux | linux | >= ef489749aae508e6f17886775c075f12ff919fb1 < ae68d93354e5bf5191ee673982251864ea24dd5c | ae68d93354e5bf5191ee673982251864ea24dd5c |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.92-1 | 5.10.92-1 |
| linux | linux_kernel | >= 0 < 5.15.15-1 | 5.15.15-1 |
| linux | linux_kernel | >= 0 < 5.15.15-1 | 5.15.15-1 |
| linux | linux_kernel | >= 0 < 5.15.15-1 | 5.15.15-1 |
| linux | linux_kernel | >= 4.14.98 < 4.14.258 | 4.14.258 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: seg6: fix the iif in the IPv6 socket control block
vendor_redhat·2024-05-24·CVSS 5.5
CVE-2021-47515 [MEDIUM] CWE-476 kernel: seg6: fix the iif in the IPv6 socket control block
kernel: seg6: fix the iif in the IPv6 socket control block
In the Linux kernel, the following vulnerability has been resolved:
seg6: fix the iif in the IPv6 socket control block
When an IPv4 packet is received, the ip_rcv_core(...) sets the receiving
interface index into the IPv4 socket control block (v5.16-rc4,
net/ipv4/ip_input.c line 510):
IPCB(skb)->iif = skb->skb_iif;
If that IPv4 packet is meant to be encapsulated in an outer IPv6+SRH
header, the seg6_do_srh_encap(...) performs the required encapsulation.
In this case, the seg6_do_srh_encap function clears the IPv6 socket control
block (v5.16-rc4 net/ipv6/seg6_iptunnel.c line 163):
memset(IP6CB(skb), 0, sizeof(*IP6CB(skb)));
The memset(...) was introduced in commit ef489749aae5 ("ipv6: sr: clear
IP6CB(skb) on SRH ip4ip6 encapsulatio
Debian
CVE-2021-47515: linux - In the Linux kernel, the following vulnerability has been resolved: seg6: fix t...
vendor_debian·2021·CVSS 5.5
CVE-2021-47515 [MEDIUM] CVE-2021-47515: linux - In the Linux kernel, the following vulnerability has been resolved: seg6: fix t...
In the Linux kernel, the following vulnerability has been resolved: seg6: fix the iif in the IPv6 socket control block When an IPv4 packet is received, the ip_rcv_core(...) sets the receiving interface index into the IPv4 socket control block (v5.16-rc4, net/ipv4/ip_input.c line 510): IPCB(skb)->iif = skb->skb_iif; If that IPv4 packet is meant to be encapsulated in an outer IPv6+SRH header, the seg6_do_srh_encap(...) performs the required encapsulation. In this case, the seg6_do_srh_encap function clears the IPv6 socket control block (v5.16-rc4 net/ipv6/seg6_iptunnel.c line 163): memset(IP6CB(skb), 0, sizeof(*IP6CB(skb))); The memset(...) was introduced in commit ef489749aae5 ("ipv6: sr: clear IP6CB(skb) on SRH ip4ip6 encapsulation") a long time ago (2019-01-29). Since the IPv6 socket cont
OSV
CVE-2021-47515: In the Linux kernel, the following vulnerability has been resolved: seg6: fix the iif in the IPv6 socket control block When an IPv4 packet is received
osv·2024-05-24·CVSS 5.5
CVE-2021-47515 [MEDIUM] CVE-2021-47515: In the Linux kernel, the following vulnerability has been resolved: seg6: fix the iif in the IPv6 socket control block When an IPv4 packet is received
In the Linux kernel, the following vulnerability has been resolved: seg6: fix the iif in the IPv6 socket control block When an IPv4 packet is received, the ip_rcv_core(...) sets the receiving interface index into the IPv4 socket control block (v5.16-rc4, net/ipv4/ip_input.c line 510): IPCB(skb)->iif = skb->skb_iif; If that IPv4 packet is meant to be encapsulated in an outer IPv6+SRH header, the seg6_do_srh_encap(...) performs the required encapsulation. In this case, the seg6_do_srh_encap function clears the IPv6 socket control block (v5.16-rc4 net/ipv6/seg6_iptunnel.c line 163): memset(IP6CB(skb), 0, sizeof(*IP6CB(skb))); The memset(...) was introduced in commit ef489749aae5 ("ipv6: sr: clear IP6CB(skb) on SRH ip4ip6 encapsulation") a long time ago (2019-01-29). Since the IPv6 socket cont
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/6431e71093f3da586a00c6d931481ffb0dc2db0ehttps://git.kernel.org/stable/c/666521b3852d2b2f52d570f9122b1e4b50d96831https://git.kernel.org/stable/c/98adb2bbfa407c9290bda299d4c6f7a1c4ebd5e1https://git.kernel.org/stable/c/ae68d93354e5bf5191ee673982251864ea24dd5chttps://git.kernel.org/stable/c/b16d412e5f79734033df04e97d7ea2f50a8e9fe3https://git.kernel.org/stable/c/ef8804e47c0a44ae106ead1740408af5ea6c6ee9https://git.kernel.org/stable/c/6431e71093f3da586a00c6d931481ffb0dc2db0ehttps://git.kernel.org/stable/c/666521b3852d2b2f52d570f9122b1e4b50d96831https://git.kernel.org/stable/c/98adb2bbfa407c9290bda299d4c6f7a1c4ebd5e1https://git.kernel.org/stable/c/ae68d93354e5bf5191ee673982251864ea24dd5chttps://git.kernel.org/stable/c/b16d412e5f79734033df04e97d7ea2f50a8e9fe3https://git.kernel.org/stable/c/ef8804e47c0a44ae106ead1740408af5ea6c6ee9
2024-05-24
Published