Input validation error in Linux kernel - CVE-2011-3188
Published: May 25, 2012 / Updated: August 11, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to #BASIC_IMPACT#.
The (1) IPv4 and (2) IPv6 implementations in the Linux kernel before 3.1 use a modified MD4 algorithm to generate sequence numbers and Fragment Identification values, which makes it easier for remote attackers to cause a denial of service (disrupted networking) or hijack network sessions by predicting these values and sending crafted packets.
Affected software
Amazon Linux AMI
IBM Storwize V3500
IBM Storwize V3700
IBM Storwize V5000
IBM Storwize V7000
How to mitigate CVE-2011-3188
IBM Storwize V3500 - update to 7.1.0.0
IBM Storwize V3700 - update to 7.1.0.0
IBM Storwize V5000 - update to 7.1.0.0
IBM Storwize V7000 - update to 7.1.0.0
External References
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=6e5714eaf77d79ae1c8b47e3e040ff5411b717ec
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=bc0b96b54a21246e377122d54569eef71cec535f
- http://marc.info/?l=bugtraq&m=139447903326211&w=2
- http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.1
- http://www.openwall.com/lists/oss-security/2011/08/23/2
- https://bugzilla.redhat.com/show_bug.cgi?id=732658
- https://github.com/torvalds/linux/commit/6e5714eaf77d79ae1c8b47e3e040ff5411b717ec
- https://github.com/torvalds/linux/commit/bc0b96b54a21246e377122d54569eef71cec535f
- https://support.f5.com/csp/article/K15301?utm_source=f5support&utm_medium=RSS