First published: Thu Oct 11 2012(Updated: )
A denial of service flaw was found in the way ibacm, an InfiniBand communication manager assistant, performed management of reference counts for multicast connections. The default reference count value for multicast connection is set to zero and when the multicast connection got released, an attempt was made to free it, possibly resulting in ib_acm service / daemon crash. Upstream patch: [1] <a href="http://git.openfabrics.org/git?p=~shefty/ibacm.git;a=commit;h=c7d28b35d64333c262de3ec972c426423dadccf9">http://git.openfabrics.org/git?p=~shefty/ibacm.git;a=commit;h=c7d28b35d64333c262de3ec972c426423dadccf9</a>
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
OpenFabrics IBA Cm | <=1.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-4517 is categorized as a denial of service vulnerability.
To fix CVE-2012-4517, upgrade to a version of ibacm that exceeds 1.0.5.
CVE-2012-4517 affects ibacm versions 1.0.5 and earlier.
CVE-2012-4517 enables denial of service attacks by improperly managing reference counts.
Yes, CVE-2012-4517 can be exploited relatively easily due to its nature of managing multicast connections.