REDHAT-BUG-1182059: Medium severity red hat iptables-services vulnerability

Published Jan 14, 2015
·
Updated

It was reported [1] that iptables can allow protocols that do not have a protocol handler kernel module loaded.

Given following iptables ruleset: -P FORWARD DROP -A FORWARD -m sctp --dport 9 -j ACCEPT -A FORWARD -p tcp --dport 80 -j ACCEPT -A FORWARD -p tcp -m conntrack -m state ESTABLISHED,RELATED -j ACCEPT

One would assume that this allows SCTP on port 9 and TCP on port 80. Unfortunately, if the SCTP conntrack module is not loaded, this allows all SCTP communication to pass through, i.e. -p sctp -j ACCEPT

[1]: http://www.spinics.net/lists/netfilter-devel/msg33430.html

Affected Software

1 affected component
netfilter iptables

Event History

Jan 14, 2015
Data Sourced
via Red Hat·11:16 AM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

When is this ruleset behavior exposed?

It is exposed when an iptables rule uses the SCTP match, such as "-m sctp --dport 9", but the SCTP conntrack protocol handler module is not loaded. In that condition, the port-specific SCTP rule can permit all SCTP traffic rather than only traffic to the intended port.

2

What traffic could an attacker send if the condition is present?

An attacker able to send SCTP traffic through the affected FORWARD path could communicate over SCTP to ports other than the explicitly allowed port. The described policy's default FORWARD DROP setting does not prevent this unintended SCTP allowance.

3

How can administrators assess whether their policy is affected?

Review FORWARD-chain rules for SCTP port matching and determine whether the SCTP conntrack protocol handler module is loaded. A configuration that expects a rule such as "-m sctp --dport 9" to restrict SCTP to that port is affected if the handler is absent.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203