Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.kernel > #64692

Bug#934168: linux-image-4.19.0-5-amd64: iptables-restore may result in NULL pointer dereference at nf_tables_newrule on startup

Path csiph.com!aioe.org!bofh.it!news.nic.it!robomod
From Salvatore Bonaccorso <carnil@debian.org>
Newsgroups linux.debian.bugs.dist, linux.debian.kernel
Subject Bug#934168: linux-image-4.19.0-5-amd64: iptables-restore may result in NULL pointer dereference at nf_tables_newrule on startup
Date Wed, 07 Aug 2019 22:50:01 +0200
Message-ID <ysB2F-4ep-3@gated-at.bofh.it> (permalink)
References <ysB2F-4ep-5@gated-at.bofh.it> <ysB2F-4ep-5@gated-at.bofh.it>
X-Original-To Elias Werberich <elias@werberich.de>, 934168@bugs.debian.org
X-Mailbox-Line From debian-bugs-dist-request@lists.debian.org Wed Aug 7 20:45:11 2019
Old-Return-Path <debbugs@buxtehude.debian.org>
X-Spam-Flag NO
X-Spam-Score -4
Reply-To Salvatore Bonaccorso <carnil@debian.org>, 934168@bugs.debian.org
Original-Sender Salvatore Bonaccorso <salvatore.bonaccorso@gmail.com>
Resent-To debian-bugs-dist@lists.debian.org
Resent-Cc Debian Kernel Team <debian-kernel@lists.debian.org>
X-Debian-Pr-Message followup 934168
X-Debian-Pr-Package src:linux
X-Debian-Pr-Source linux
X-Spam-Bayes score:0.0000 Tokens: new, 17; hammy, 150; neutral, 150; spammy, 0. spammytokens: hammytokens:0.000-+--H*F:U*carnil, 0.000-+--Hx-spam-relays-external:sk:salvato, 0.000-+--H*u:1.10.1, 0.000-+--H*UA:1.10.1, 0.000-+--H*u:2018-07-13
Dkim-Signature v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=sender:date:from:to:subject:message-id:references:mime-version :content-disposition:in-reply-to:user-agent; bh=uM+zl4zqe63ADFlNbqmvWO8BlswqiSGcU22l5s0kbrs=; b=JpONXFz5L5YjWw7lBfty+l50yLOKYW3pYDXrFbJZGTFQ30tgywgL/POocSUO5LBJT6 z6PG8p9FWhioy1dyhybMbnv3C/Leo0Z88KBfliuGPYF+tQOuW99fOuvISsaeD2HBPPEK Vr9CGMUtj4TJSjYL2PhwsvayB025i1KLkZyIYzCgDhCwJq5LdzUFrf7pZVYFyIUxRMri ck62K5OzKZrBiLF9+CyFpkPXQZhD5gUkTVcZ/KiSA7tTbU5YxGyWC+2WSDVc5YKRhhCa SPvMIOCvZIaA6QQH0N//YewVTCvjp2l45Yns45v98yA2MCij9uOi+1dABS/Ovhn2kIV8 8z0A==
X-Google-Dkim-Signature v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:sender:date:from:to:subject:message-id :references:mime-version:content-disposition:in-reply-to:user-agent; bh=uM+zl4zqe63ADFlNbqmvWO8BlswqiSGcU22l5s0kbrs=; b=b9VSuR1wUFfTGMeWH1dV0pmi1VShOiXsoUlzy/NKKqrRF7TXdKS0cUfw0QWb+3TnSz kyJijwTRSokNjqdppdB7qhLr4DHE2gTzeavqgYccaZ/GtN2LbMczrqpI6h06vK+97HqI xhiSIPy4ZCGn8ARZM5mY9Hhc16YEdf1CcaJaqvbEWhKTt2EmuT/0yBGZorjKmejq5Ihb 2SnHlbmKs1ncTBF/N6rLF/1u0AggGj0wo1yftfxKVTBbtxv4+pOMBAfNHtgpRWU/jki5 TmoaVmONd/WsAF4Kz15ToQWeDAp9RiQoMdtOl9Op7Kmrpvc5C09b1FP+Vg+nnm72piOz G+rg==
X-Gm-Message-State APjAAAXHhpPwHpYZGMEscdq/QM6NarhPVl7EbsQp3Dgk/lGl83Z+zQ7w RTITlBVcorZ9dppIfVt14KZBnPb6lGU=
X-Google-SMTP-Source APXvYqxtgt1yZjHvzdY8tHkoT5gYnYxX23lOGh9Z3ZIISgDHyw7/TEv63W6Tve6q+UkNvOLua5Q5UQ==
X-Received by 2002:a17:906:1b0d:: with SMTP id o13mr10138030ejg.96.1565210573752; Wed, 07 Aug 2019 13:42:53 -0700 (PDT)
Sender robomod@news.nic.it
MIME-Version 1.0
Content-Type text/plain; charset=us-ascii
Content-Disposition inline
User-Agent Mutt/1.10.1 (2018-07-13)
X-Debian-Message from BTS
X-Mailing-List <debian-bugs-dist@lists.debian.org> archive/latest/1550496
List-ID <debian-bugs-dist.lists.debian.org>
List-URL <https://lists.debian.org/debian-bugs-dist/>
Approved robomod@news.nic.it
Lines 74
Organization linux.* mail to news gateway
X-Original-Date Wed, 7 Aug 2019 22:42:51 +0200
X-Original-Message-ID <20190807204251.GA4067@eldamar.local>
X-Original-References <e235c6cc-1620-a43d-828d-fe55e9fc8b0a@werberich.de> <e235c6cc-1620-a43d-828d-fe55e9fc8b0a@werberich.de>
X-Original-Sender Salvatore Bonaccorso <salvatore.bonaccorso@gmail.com>
Xref csiph.com linux.debian.bugs.dist:968581 linux.debian.kernel:64692

Cross-posted to 2 groups.

Show key headers only | View raw


Control: forcemerge 931330 934168

hi Elias,

On Wed, Aug 07, 2019 at 06:51:12PM +0200, Elias Werberich wrote:
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA512
> 
> Package: src:linux
> Version: 4.19.37-5+deb10u1
> Severity: normal
> X-Debbugs-Cc: elias@werberich.de
> 
> 
> Dear Kernel Maintainer,
> 
> I found a reproducible bug which causes a linux kernel oops if
> netfilter-persistence.service tries to load IPv4 firewall rules on
> startup by calling iptables-restore with the following content as
> input:
> 
> *filter
> :INPUT ACCEPT [0:0]
> :FORWARD DROP [0:0]
> :OUTPUT ACCEPT [0:0]
> :MY-ICMP - [0:0]
> - -A INPUT -j MY-ICMP
> - -A MY-ICMP -p icmp -m icmp --icmp-type 3 -j ACCEPT
> - -A MY-ICMP -p icmp -m icmp --icmp-type 11 -j ACCEPT
> - -A MY-ICMP -p icmp -m icmp --icmp-type 8 -m limit --limit 4/sec -j ACCEPT
> COMMIT
> 
> I was able to create this simple ruleset out of a more complex firewall configuration.
> This kernel oops appears on nine out of ten startups/reboots.
> If it appears, iptables/nftables are not usable anymore.
> For more details, consult kernel log.
> 
> Steps to reproduce the kernel oops:
> 
> # Install a fresh, minimal Debian 10 Buster system. (e.g. new VM)
> $ apt update
> $ apt install iptables iptables-persistent
> # Save IPv4 rules on installation, do not save IPv6 rules.
> $ cat << \EOF > /etc/iptables/rules.v4
> *filter
> :INPUT ACCEPT [0:0]
> :FORWARD DROP [0:0]
> :OUTPUT ACCEPT [0:0]
> :MY-ICMP - [0:0]
> - -A INPUT -j MY-ICMP
> - -A MY-ICMP -p icmp -m icmp --icmp-type 3 -j ACCEPT
> - -A MY-ICMP -p icmp -m icmp --icmp-type 11 -j ACCEPT
> - -A MY-ICMP -p icmp -m icmp --icmp-type 8 -m limit --limit 4/sec -j ACCEPT
> COMMIT
> EOF
> $ reboot
> 
> You may need to reboot a second or third time, if it does not appear
> on the first startup.
> 
> I was able to reproduce this on AMD64 using VirtualBox VM and a
> cloud server provider.  It may cause a broken firewall configuration
> which leads to a security issue if you reboot without monitoring.

Thanks for the reproducing instructions. This looks the same as the
bug reported at https://bugzilla.kernel.org/show_bug.cgi?id=203681
which is #931330.

This should be fixed in 5.2.6-1. But might need to check which
commit(s) fix the issue and see they are already backported to the
4.19.x stable series as well.

Regards,
Salvatore

Back to linux.debian.kernel | Previous | NextNext in thread | Find similar | Unroll thread


Thread

Bug#934168: linux-image-4.19.0-5-amd64: iptables-restore may result in NULL pointer dereference at nf_tables_newrule on startup Salvatore Bonaccorso <carnil@debian.org> - 2019-08-07 22:50 +0200
  Processed: Re: Bug#934168: linux-image-4.19.0-5-amd64:  iptables-restore may result in NULL pointer dereference at nf_tables_newrule  on startup "Debian Bug Tracking System" <owner@bugs.debian.org> - 2019-08-07 22:50 +0200
  Bug#934168: linux-image-4.19.0-5-amd64: iptables-restore may result in NULL pointer dereference at nf_tables_newrule on startup Salvatore Bonaccorso <carnil@debian.org> - 2019-08-19 22:40 +0200

csiph-web