Bug in network protocol causes crashes
Summary
Since Linux 2.6.36 the IGMP code of the IPv4 stack had contained a bug that could trigger a kernel panic (CVE-2012-0207). Simon McVittie found it after a notebook crashed several times: a crash log recorded with netconsole revealed a division by zero when processing an IGMP packet. The bug was fixed in 3.0.17, 3.1.9 and 3.2.1.
Ideas
- IGMP manages receiver groups for multicast, for example for IPTV.
- A single network packet could crash the system.
- netconsole sends kernel messages over the network and thus saves crash logs.
Insights
- Persistent crashes can often only be explained with continuous logging outside the system.
- Rarely noticed protocols are also active on normal computers.
Facts
- IGMP versions 2 and 3 were affected.
- The cause was a division by zero.
- Attacks were easy on the local network and possible from outside via unicast; a firewall can block IGMP.
References
Critique
- The report does not say which distribution kernels already contained the fix.
Recommendations
- Set up netconsole or a remote log to be able to trace kernel crashes.
- Filter multicast and IGMP traffic at network boundaries if it is not needed.
Links to the original source and the Web Archive open in a new tab.