CVE-2017-1000112: Race Condition
A memory corruption issue was found in the Linux kernel.
When building a UFO packet with MSGMORE ipappenddata() calls ipufoappenddata() to append. However in between two send() calls, the append path can be switched from UFO to non-UFO one, which leads to a memory corruption.
In case UFO packet lengths exceeds MTU, copy = maxfraglen - skb->len becomes negative on the non-UFO path and the branch to allocate new skb is taken. This triggers fragmentation and computation of fraggap = skbprev->len - maxfraglen. Fraggap can exceed MTU, causing copy = datalen - transhdrlen - fraggap to become negative. Subsequently skbcopyandcsumbits() writes out-of-bounds.
Introducing commit:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=e89e9cf539a2
Other sources
Linux kernel: Exploitable memory corruption due to UFO to non-UFO path switch. When building a UFO packet with MSGMORE ipappenddata() calls ipufoappenddata() to append. However in between two send() calls, the append path can be switched from UFO to non-UFO one, which leads to a memory corruption. In case UFO packet lengths exceeds MTU, copy = maxfraglen - skb->len becomes negative on the non-UFO path and the branch to allocate new skb is taken. This triggers fragmentation and computation of fraggap = skbprev->len - maxfraglen. Fraggap can exceed MTU, causing copy = datalen - transhdrlen - fraggap to become negative. Subsequently skbcopyandcsumbits() writes out-of-bounds. A similar issue is present in IPv6 code. The bug was introduced in e89e9cf539a2 ("[IPv4/IPv6]: UFO Scatter-gather approach") on Oct 18 2005.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-1000112?
CVE-2017-1000112 has been classified as a high-severity vulnerability due to the potential for memory corruption.
How do I fix CVE-2017-1000112?
To remediate CVE-2017-1000112, you should upgrade to a patched version of the Linux kernel, specifically versions 4.19.249-2, 5.10.197-1, or later.
Which Linux kernel versions are affected by CVE-2017-1000112?
CVE-2017-1000112 affects Linux kernel versions between 2.6.15 and 4.12.7.
What can happen if I am vulnerable to CVE-2017-1000112?
If your system is vulnerable to CVE-2017-1000112, it could lead to memory corruption that may be exploited by attackers to cause system instability or execute arbitrary code.
Is CVE-2017-1000112 specific to a certain distribution of Linux?
No, CVE-2017-1000112 is a vulnerability found in the Linux kernel and can affect multiple distributions that utilize the affected kernel versions.