First published: Wed Jul 20 2011(Updated: )
IPv6 fragment identification generation is way beyond what we use for IPv4 : It uses a single generator. Its not scalable and allows DOS attacks. Now inetpeer is IPv6 aware, we can use it to provide a more secure and scalable frag ident generator (per destination, instead of system wide) This patch : 1) defines a new secure_ipv6_id() helper 2) extends inet_getid() to provide 32bit results 3) extends ipv6_select_ident() with a new dest parameter <a href="http://thread.gmane.org/gmane.linux.network/201773">http://thread.gmane.org/gmane.linux.network/201773</a> Acknowledgements: Red Hat would like to thank Fernando Gont for reporting this issue.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Linux kernel | <3.1 | |
Redhat Enterprise Linux | =4.0 | |
Redhat Enterprise Mrg | =2.0 | |
debian/linux-2.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.