kernel-packages team mailing list archive
-
kernel-packages team
-
Mailing list archive
-
Message #00432
[Bug 1202990] [NEW] CVE-2013-4125
*** This bug is a security vulnerability ***
Public security bug reported:
The fib6_add_rt2node function in net/ipv6/ip6_fib.c in the IPv6 stack in
the Linux kernel through 3.10.1 does not properly handle Router
Advertisement (RA) messages in certain circumstances involving three
routes that initially qualified for membership in an ECMP route set
until a change occurred for one of the first two routes, which allows
remote attackers to cause a denial of service (system crash) via a
crafted sequence of messages.
Break-Fix: 51ebd3181572af8d5076808dab2682d800f6da5d
307f2fb95e9b96b3577916e73d92e104f8f26494
** Affects: linux (Ubuntu)
Importance: Medium
Status: New
** Affects: linux-armadaxp (Ubuntu)
Importance: Medium
Status: Invalid
** Affects: linux-ec2 (Ubuntu)
Importance: Medium
Status: Invalid
** Affects: linux-fsl-imx51 (Ubuntu)
Importance: Medium
Status: Invalid
** Affects: linux-lts-backport-maverick (Ubuntu)
Importance: Undecided
Status: New
** Affects: linux-lts-backport-natty (Ubuntu)
Importance: Undecided
Status: New
** Affects: linux-lts-quantal (Ubuntu)
Importance: Medium
Status: Invalid
** Affects: linux-lts-raring (Ubuntu)
Importance: Medium
Status: Invalid
** Affects: linux-mvl-dove (Ubuntu)
Importance: Medium
Status: Invalid
** Affects: linux-ti-omap4 (Ubuntu)
Importance: Medium
Status: New
** Affects: linux (Ubuntu Lucid)
Importance: Medium
Status: New
** Affects: linux-armadaxp (Ubuntu Lucid)
Importance: Medium
Status: Invalid
** Affects: linux-ec2 (Ubuntu Lucid)
Importance: Medium
Status: New
** Affects: linux-fsl-imx51 (Ubuntu Lucid)
Importance: Medium
Status: Invalid
** Affects: linux-lts-backport-maverick (Ubuntu Lucid)
Importance: Undecided
Status: New
** Affects: linux-lts-backport-natty (Ubuntu Lucid)
Importance: Undecided
Status: New
** Affects: linux-lts-quantal (Ubuntu Lucid)
Importance: Medium
Status: Invalid
** Affects: linux-lts-raring (Ubuntu Lucid)
Importance: Medium
Status: Invalid
** Affects: linux-mvl-dove (Ubuntu Lucid)
Importance: Medium
Status: Invalid
** Affects: linux-ti-omap4 (Ubuntu Lucid)
Importance: Medium
Status: Invalid
** Affects: linux (Ubuntu Precise)
Importance: Medium
Status: New
** Affects: linux-armadaxp (Ubuntu Precise)
Importance: Medium
Status: New
** Affects: linux-ec2 (Ubuntu Precise)
Importance: Medium
Status: Invalid
** Affects: linux-fsl-imx51 (Ubuntu Precise)
Importance: Medium
Status: Invalid
** Affects: linux-lts-backport-maverick (Ubuntu Precise)
Importance: Undecided
Status: New
** Affects: linux-lts-backport-natty (Ubuntu Precise)
Importance: Undecided
Status: New
** Affects: linux-lts-quantal (Ubuntu Precise)
Importance: Medium
Status: New
** Affects: linux-lts-raring (Ubuntu Precise)
Importance: Medium
Status: New
** Affects: linux-mvl-dove (Ubuntu Precise)
Importance: Medium
Status: Invalid
** Affects: linux-ti-omap4 (Ubuntu Precise)
Importance: Medium
Status: New
** Affects: linux (Ubuntu Quantal)
Importance: Medium
Status: New
** Affects: linux-armadaxp (Ubuntu Quantal)
Importance: Medium
Status: New
** Affects: linux-ec2 (Ubuntu Quantal)
Importance: Medium
Status: Invalid
** Affects: linux-fsl-imx51 (Ubuntu Quantal)
Importance: Medium
Status: Invalid
** Affects: linux-lts-backport-maverick (Ubuntu Quantal)
Importance: Undecided
Status: New
** Affects: linux-lts-backport-natty (Ubuntu Quantal)
Importance: Undecided
Status: New
** Affects: linux-lts-quantal (Ubuntu Quantal)
Importance: Medium
Status: Invalid
** Affects: linux-lts-raring (Ubuntu Quantal)
Importance: Medium
Status: Invalid
** Affects: linux-mvl-dove (Ubuntu Quantal)
Importance: Medium
Status: Invalid
** Affects: linux-ti-omap4 (Ubuntu Quantal)
Importance: Medium
Status: New
** Affects: linux (Ubuntu Raring)
Importance: Medium
Status: New
** Affects: linux-armadaxp (Ubuntu Raring)
Importance: Medium
Status: Invalid
** Affects: linux-ec2 (Ubuntu Raring)
Importance: Medium
Status: Invalid
** Affects: linux-fsl-imx51 (Ubuntu Raring)
Importance: Medium
Status: Invalid
** Affects: linux-lts-backport-maverick (Ubuntu Raring)
Importance: Undecided
Status: New
** Affects: linux-lts-backport-natty (Ubuntu Raring)
Importance: Undecided
Status: New
** Affects: linux-lts-quantal (Ubuntu Raring)
Importance: Medium
Status: Invalid
** Affects: linux-lts-raring (Ubuntu Raring)
Importance: Medium
Status: Invalid
** Affects: linux-mvl-dove (Ubuntu Raring)
Importance: Medium
Status: Invalid
** Affects: linux-ti-omap4 (Ubuntu Raring)
Importance: Medium
Status: New
** Affects: linux (Ubuntu Saucy)
Importance: Medium
Status: New
** Affects: linux-armadaxp (Ubuntu Saucy)
Importance: Medium
Status: Invalid
** Affects: linux-ec2 (Ubuntu Saucy)
Importance: Medium
Status: Invalid
** Affects: linux-fsl-imx51 (Ubuntu Saucy)
Importance: Medium
Status: Invalid
** Affects: linux-lts-backport-maverick (Ubuntu Saucy)
Importance: Undecided
Status: New
** Affects: linux-lts-backport-natty (Ubuntu Saucy)
Importance: Undecided
Status: New
** Affects: linux-lts-quantal (Ubuntu Saucy)
Importance: Medium
Status: Invalid
** Affects: linux-lts-raring (Ubuntu Saucy)
Importance: Medium
Status: Invalid
** Affects: linux-mvl-dove (Ubuntu Saucy)
Importance: Medium
Status: Invalid
** Affects: linux-ti-omap4 (Ubuntu Saucy)
Importance: Medium
Status: New
** Tags: kernel-cve-tracking-bug
** Tags added: kernel-cve-tracking-bug
** Information type changed from Public to Public Security
** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2013-4125
--
You received this bug notification because you are a member of Kernel
Packages, which is subscribed to linux in Ubuntu.
https://bugs.launchpad.net/bugs/1202990
Title:
CVE-2013-4125
Status in “linux” package in Ubuntu:
New
Status in “linux-armadaxp” package in Ubuntu:
Invalid
Status in “linux-ec2” package in Ubuntu:
Invalid
Status in “linux-fsl-imx51” package in Ubuntu:
Invalid
Status in “linux-lts-backport-maverick” package in Ubuntu:
New
Status in “linux-lts-backport-natty” package in Ubuntu:
New
Status in “linux-lts-quantal” package in Ubuntu:
Invalid
Status in “linux-lts-raring” package in Ubuntu:
Invalid
Status in “linux-mvl-dove” package in Ubuntu:
Invalid
Status in “linux-ti-omap4” package in Ubuntu:
New
Status in “linux” source package in Lucid:
New
Status in “linux-armadaxp” source package in Lucid:
Invalid
Status in “linux-ec2” source package in Lucid:
New
Status in “linux-fsl-imx51” source package in Lucid:
Invalid
Status in “linux-lts-backport-maverick” source package in Lucid:
New
Status in “linux-lts-backport-natty” source package in Lucid:
New
Status in “linux-lts-quantal” source package in Lucid:
Invalid
Status in “linux-lts-raring” source package in Lucid:
Invalid
Status in “linux-mvl-dove” source package in Lucid:
Invalid
Status in “linux-ti-omap4” source package in Lucid:
Invalid
Status in “linux” source package in Precise:
New
Status in “linux-armadaxp” source package in Precise:
New
Status in “linux-ec2” source package in Precise:
Invalid
Status in “linux-fsl-imx51” source package in Precise:
Invalid
Status in “linux-lts-backport-maverick” source package in Precise:
New
Status in “linux-lts-backport-natty” source package in Precise:
New
Status in “linux-lts-quantal” source package in Precise:
New
Status in “linux-lts-raring” source package in Precise:
New
Status in “linux-mvl-dove” source package in Precise:
Invalid
Status in “linux-ti-omap4” source package in Precise:
New
Status in “linux” source package in Quantal:
New
Status in “linux-armadaxp” source package in Quantal:
New
Status in “linux-ec2” source package in Quantal:
Invalid
Status in “linux-fsl-imx51” source package in Quantal:
Invalid
Status in “linux-lts-backport-maverick” source package in Quantal:
New
Status in “linux-lts-backport-natty” source package in Quantal:
New
Status in “linux-lts-quantal” source package in Quantal:
Invalid
Status in “linux-lts-raring” source package in Quantal:
Invalid
Status in “linux-mvl-dove” source package in Quantal:
Invalid
Status in “linux-ti-omap4” source package in Quantal:
New
Status in “linux” source package in Raring:
New
Status in “linux-armadaxp” source package in Raring:
Invalid
Status in “linux-ec2” source package in Raring:
Invalid
Status in “linux-fsl-imx51” source package in Raring:
Invalid
Status in “linux-lts-backport-maverick” source package in Raring:
New
Status in “linux-lts-backport-natty” source package in Raring:
New
Status in “linux-lts-quantal” source package in Raring:
Invalid
Status in “linux-lts-raring” source package in Raring:
Invalid
Status in “linux-mvl-dove” source package in Raring:
Invalid
Status in “linux-ti-omap4” source package in Raring:
New
Status in “linux” source package in Saucy:
New
Status in “linux-armadaxp” source package in Saucy:
Invalid
Status in “linux-ec2” source package in Saucy:
Invalid
Status in “linux-fsl-imx51” source package in Saucy:
Invalid
Status in “linux-lts-backport-maverick” source package in Saucy:
New
Status in “linux-lts-backport-natty” source package in Saucy:
New
Status in “linux-lts-quantal” source package in Saucy:
Invalid
Status in “linux-lts-raring” source package in Saucy:
Invalid
Status in “linux-mvl-dove” source package in Saucy:
Invalid
Status in “linux-ti-omap4” source package in Saucy:
New
Bug description:
The fib6_add_rt2node function in net/ipv6/ip6_fib.c in the IPv6 stack
in the Linux kernel through 3.10.1 does not properly handle Router
Advertisement (RA) messages in certain circumstances involving three
routes that initially qualified for membership in an ECMP route set
until a change occurred for one of the first two routes, which allows
remote attackers to cause a denial of service (system crash) via a
crafted sequence of messages.
Break-Fix: 51ebd3181572af8d5076808dab2682d800f6da5d
307f2fb95e9b96b3577916e73d92e104f8f26494
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1202990/+subscriptions
Follow ups
-
[Bug 1202990] Re: CVE-2013-4125
From: Rolf Leggewie, 2016-04-24
-
[Bug 1202990] Re: CVE-2013-4125
From: Steve Beattie, 2016-02-10
-
[Bug 1202990] Re: CVE-2013-4125
From: Steve Beattie, 2015-12-04
-
[Bug 1202990] Re: CVE-2013-4125
From: Steve Beattie, 2015-12-03
-
[Bug 1202990] Re: CVE-2013-4125
From: John Johansen, 2015-05-08
-
[Bug 1202990] Re: CVE-2013-4125
From: Jamie Strandboge, 2013-11-12
-
[Bug 1202990] Re: CVE-2013-4125
From: Jamie Strandboge, 2013-11-12
-
[Bug 1202990] Re: CVE-2013-4125
From: Jamie Strandboge, 2013-11-12
-
[Bug 1202990]
From: Jamie Strandboge, 2013-11-12
-
[Bug 1202990]
From: Jamie Strandboge, 2013-11-12
-
[Bug 1202990] Re: CVE-2013-4125
From: Launchpad Bug Tracker, 2013-08-20
-
[Bug 1202990] Re: CVE-2013-4125
From: Launchpad Bug Tracker, 2013-08-20
-
[Bug 1202990] Re: CVE-2013-4125
From: John Johansen, 2013-08-16
-
[Bug 1202990] Re: CVE-2013-4125
From: John Johansen, 2013-08-13
-
[Bug 1202990] Re: CVE-2013-4125
From: John Johansen, 2013-08-01
-
[Bug 1202990] Re: CVE-2013-4125
From: John Johansen, 2013-07-25
-
[Bug 1202990] Re: CVE-2013-4125
From: John Johansen, 2013-07-19
-
[Bug 1202990] [NEW] CVE-2013-4125
From: John Johansen, 2013-07-19
References