CVE-2011-3593: Medium severity red hat enterprise linux vulnerability

Published Oct 3, 2011
·
Updated

A certain Red Hat patch to the vlanhwacceldoreceive function in net/8021q/vlancore.c in the Linux kernel 2.6.32 on Red Hat Enterprise Linux (RHEL) 6 allows remote attackers to cause a denial of service (system crash) via priority-tagged VLAN frames.

Other sources

A partner reported that frames with priority tags only (VID=0 in the frame), could cause a panic on some drivers. The backtrace would look like this:

Pid: 0, comm: swapper Not tainted 2.6.32-197.el6 RIP: 0010:[<ffffffff814c6b46>] [<ffffffff814c6b46>] vlanhwacceldoreceive+0x7 6/0x110 RSP: 0018:ffff880028203c30 EFLAGS: 00010283 RAX: ffff10015867e7b0 RBX: ffff88012e69c8c0 RCX: 0000000000000000 RDX: 0000000000000000 RSI: ffff88012e69c8c0 RDI: ffff88012e69c8c0 RBP: ffff880028203c50 R08: 0000000000000001 R09: 0000000000000008 R10: 0000000000000001 R11: 0000000000000000 R12: ffff88013047e6e0 R13: ffff88013047e020 R14: ffff88012c893010 R15: ffffc900127dd028 FS: 0000000000000000(0000) GS:ffff880028200000(0000) knlGS:0000000000000000 CS: 0010 DS: 0018 ES: 0018 CR0: 000000008005003b CR2: 000000364a4abd60 CR3: 000000012b417000 CR4: 00000000000006f0 DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 DR3: 0000000000000000 DR6: 00000000ffff0ff0 DR7: 0000000000000400 Process swapper (pid: 0, threadinfo ffffffff81a00000, task ffffffff81a8d020) Stack: ffff880028203d60 ffff88012e69c8c0 ffff880129efb258 ffff8801337a9800 <0> ffff880028203cb0 ffffffff8142b558 0101880028203c90 0000000000000000 <0> ffffffff00000000 ffff88002820f560 0000000028203c90 ffff88012e69c8c0 Call Trace: <IRQ> [<ffffffff8142b558>] netifreceiveskb+0x4b8/0x6e0 [<ffffffff8142d5d8>] netifreceiveskb+0x58/0x60 [<ffffffff8142d6e0>] napiskbfinish+0x50/0x70 [<ffffffff814c7244>] vlangroreceive+0x84/0xa0 [<ffffffffa030dd0b>] igbpoll+0x88b/0xe70 [igb] [<ffffffff810de607>] ? cpuquietmsk+0x77/0x130 [<ffffffff8142fe83>] netrxaction+0x103/0x2f0 [<ffffffff81072101>] dosoftirq+0xc1/0x1d0 [<ffffffff810d9410>] ? handleIRQevent+0x60/0x170 [<ffffffff8100c20c>] callsoftirq+0x1c/0x30 [<ffffffff8100de45>] dosoftirq+0x65/0xa0 [<ffffffff81071ee5>] irqexit+0x85/0x90 [<ffffffff814f4245>] doIRQ+0x75/0xf0 [<ffffffff8100ba13>] retfromintr+0x0/0x11

The partner provided a patch to demonstrate the fix, but it was a bit more complex than what we really needed and had a bug. Andy worked to create something a bit smaller and am pleased with the outcome. This code is modeled after the code that is currently upstream in vlandoreceive. If skb->dev is not a valid VLAN interface, then we can stop processing and return control to netifreceiveskb. We also set skb->pkttype = PACKETOTHERHOST so the frame is dropped in the stack quickly.

Andy has tested this patch and confirmed that the panic is prevented and everything else works as expected. Sending frames with only a priority tag results in the frames being dropped (if a device with VID 0 is not created on the host), and he also did a packet capture and noted that priority tagged frames are properly displayed with tcpdump/wireshark.

Acknowledgements:

Red Hat would like to thank Gideon Naim for reporting this issue.

Red Hat

Affected Software

3 affected components
debian/linux-2.6
redhat Enterprise Linux=6.0
Linux Linux kernel=2.6.32

Event History

Oct 3, 2011
Data Sourced
via Red Hat·05:26 AM
DescriptionSeverityAffected Software
Jun 8, 2013
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Jan 11, 2024
Data Sourced
via Launchpad·09:58 PM
Description
Sep 15, 2024
Data Sourced
via Ubuntu·10:47 PM
RemedyDescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2011-3593?

CVE-2011-3593 has a medium severity rating due to its potential to cause a denial of service.

2

How do I fix CVE-2011-3593?

To mitigate CVE-2011-3593, update the Linux kernel to a version that includes the necessary patches addressing this vulnerability.

3

Which systems are affected by CVE-2011-3593?

CVE-2011-3593 affects Red Hat Enterprise Linux 6 and the Linux kernel version 2.6.32.

4

What type of attack does CVE-2011-3593 enable?

CVE-2011-3593 allows remote attackers to conduct a denial of service attack leading to a system crash.

5

Is CVE-2011-3593 a critical vulnerability?

CVE-2011-3593 is not classified as critical but poses significant risks to system stability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203