bk99.de entertain the web since 1997

Bug in network protocol causes crashes

Summary

Since Linux 2.6.36 the IGMP code of the IPv4 stack had contained a bug that could trigger a kernel panic (CVE-2012-0207). Simon McVittie found it after a notebook crashed several times: a crash log recorded with netconsole revealed a division by zero when processing an IGMP packet. The bug was fixed in 3.0.17, 3.1.9 and 3.2.1.

Ideas

  • IGMP manages receiver groups for multicast, for example for IPTV.
  • A single network packet could crash the system.
  • netconsole sends kernel messages over the network and thus saves crash logs.

Insights

  • Persistent crashes can often only be explained with continuous logging outside the system.
  • Rarely noticed protocols are also active on normal computers.

Facts

  • IGMP versions 2 and 3 were affected.
  • The cause was a division by zero.
  • Attacks were easy on the local network and possible from outside via unicast; a firewall can block IGMP.

References

Critique

  • The report does not say which distribution kernels already contained the fix.

Recommendations

  • Set up netconsole or a remote log to be able to trace kernel crashes.
  • Filter multicast and IGMP traffic at network boundaries if it is not needed.

Read the original article

Search the Web Archive