Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.kernel > #64692
| Path | csiph.com!aioe.org!bofh.it!news.nic.it!robomod |
|---|---|
| From | Salvatore Bonaccorso <carnil@debian.org> |
| Newsgroups | linux.debian.bugs.dist, linux.debian.kernel |
| Subject | Bug#934168: linux-image-4.19.0-5-amd64: iptables-restore may result in NULL pointer dereference at nf_tables_newrule on startup |
| Date | Wed, 07 Aug 2019 22:50:01 +0200 |
| Message-ID | <ysB2F-4ep-3@gated-at.bofh.it> (permalink) |
| References | <ysB2F-4ep-5@gated-at.bofh.it> <ysB2F-4ep-5@gated-at.bofh.it> |
| X-Original-To | Elias Werberich <elias@werberich.de>, 934168@bugs.debian.org |
| X-Mailbox-Line | From debian-bugs-dist-request@lists.debian.org Wed Aug 7 20:45:11 2019 |
| Old-Return-Path | <debbugs@buxtehude.debian.org> |
| X-Spam-Flag | NO |
| X-Spam-Score | -4 |
| Reply-To | Salvatore Bonaccorso <carnil@debian.org>, 934168@bugs.debian.org |
| Original-Sender | Salvatore Bonaccorso <salvatore.bonaccorso@gmail.com> |
| Resent-To | debian-bugs-dist@lists.debian.org |
| Resent-Cc | Debian Kernel Team <debian-kernel@lists.debian.org> |
| X-Debian-Pr-Message | followup 934168 |
| X-Debian-Pr-Package | src:linux |
| X-Debian-Pr-Source | linux |
| X-Spam-Bayes | score:0.0000 Tokens: new, 17; hammy, 150; neutral, 150; spammy, 0. spammytokens: hammytokens:0.000-+--H*F:U*carnil, 0.000-+--Hx-spam-relays-external:sk:salvato, 0.000-+--H*u:1.10.1, 0.000-+--H*UA:1.10.1, 0.000-+--H*u:2018-07-13 |
| Dkim-Signature | v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=sender:date:from:to:subject:message-id:references:mime-version :content-disposition:in-reply-to:user-agent; bh=uM+zl4zqe63ADFlNbqmvWO8BlswqiSGcU22l5s0kbrs=; b=JpONXFz5L5YjWw7lBfty+l50yLOKYW3pYDXrFbJZGTFQ30tgywgL/POocSUO5LBJT6 z6PG8p9FWhioy1dyhybMbnv3C/Leo0Z88KBfliuGPYF+tQOuW99fOuvISsaeD2HBPPEK Vr9CGMUtj4TJSjYL2PhwsvayB025i1KLkZyIYzCgDhCwJq5LdzUFrf7pZVYFyIUxRMri ck62K5OzKZrBiLF9+CyFpkPXQZhD5gUkTVcZ/KiSA7tTbU5YxGyWC+2WSDVc5YKRhhCa SPvMIOCvZIaA6QQH0N//YewVTCvjp2l45Yns45v98yA2MCij9uOi+1dABS/Ovhn2kIV8 8z0A== |
| X-Google-Dkim-Signature | v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:sender:date:from:to:subject:message-id :references:mime-version:content-disposition:in-reply-to:user-agent; bh=uM+zl4zqe63ADFlNbqmvWO8BlswqiSGcU22l5s0kbrs=; b=b9VSuR1wUFfTGMeWH1dV0pmi1VShOiXsoUlzy/NKKqrRF7TXdKS0cUfw0QWb+3TnSz kyJijwTRSokNjqdppdB7qhLr4DHE2gTzeavqgYccaZ/GtN2LbMczrqpI6h06vK+97HqI xhiSIPy4ZCGn8ARZM5mY9Hhc16YEdf1CcaJaqvbEWhKTt2EmuT/0yBGZorjKmejq5Ihb 2SnHlbmKs1ncTBF/N6rLF/1u0AggGj0wo1yftfxKVTBbtxv4+pOMBAfNHtgpRWU/jki5 TmoaVmONd/WsAF4Kz15ToQWeDAp9RiQoMdtOl9Op7Kmrpvc5C09b1FP+Vg+nnm72piOz G+rg== |
| X-Gm-Message-State | APjAAAXHhpPwHpYZGMEscdq/QM6NarhPVl7EbsQp3Dgk/lGl83Z+zQ7w RTITlBVcorZ9dppIfVt14KZBnPb6lGU= |
| X-Google-SMTP-Source | APXvYqxtgt1yZjHvzdY8tHkoT5gYnYxX23lOGh9Z3ZIISgDHyw7/TEv63W6Tve6q+UkNvOLua5Q5UQ== |
| X-Received | by 2002:a17:906:1b0d:: with SMTP id o13mr10138030ejg.96.1565210573752; Wed, 07 Aug 2019 13:42:53 -0700 (PDT) |
| Sender | robomod@news.nic.it |
| MIME-Version | 1.0 |
| Content-Type | text/plain; charset=us-ascii |
| Content-Disposition | inline |
| User-Agent | Mutt/1.10.1 (2018-07-13) |
| X-Debian-Message | from BTS |
| X-Mailing-List | <debian-bugs-dist@lists.debian.org> archive/latest/1550496 |
| List-ID | <debian-bugs-dist.lists.debian.org> |
| List-URL | <https://lists.debian.org/debian-bugs-dist/> |
| Approved | robomod@news.nic.it |
| Lines | 74 |
| Organization | linux.* mail to news gateway |
| X-Original-Date | Wed, 7 Aug 2019 22:42:51 +0200 |
| X-Original-Message-ID | <20190807204251.GA4067@eldamar.local> |
| X-Original-References | <e235c6cc-1620-a43d-828d-fe55e9fc8b0a@werberich.de> <e235c6cc-1620-a43d-828d-fe55e9fc8b0a@werberich.de> |
| X-Original-Sender | Salvatore Bonaccorso <salvatore.bonaccorso@gmail.com> |
| Xref | csiph.com linux.debian.bugs.dist:968581 linux.debian.kernel:64692 |
Cross-posted to 2 groups.
Show key headers only | View raw
Control: forcemerge 931330 934168 hi Elias, On Wed, Aug 07, 2019 at 06:51:12PM +0200, Elias Werberich wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA512 > > Package: src:linux > Version: 4.19.37-5+deb10u1 > Severity: normal > X-Debbugs-Cc: elias@werberich.de > > > Dear Kernel Maintainer, > > I found a reproducible bug which causes a linux kernel oops if > netfilter-persistence.service tries to load IPv4 firewall rules on > startup by calling iptables-restore with the following content as > input: > > *filter > :INPUT ACCEPT [0:0] > :FORWARD DROP [0:0] > :OUTPUT ACCEPT [0:0] > :MY-ICMP - [0:0] > - -A INPUT -j MY-ICMP > - -A MY-ICMP -p icmp -m icmp --icmp-type 3 -j ACCEPT > - -A MY-ICMP -p icmp -m icmp --icmp-type 11 -j ACCEPT > - -A MY-ICMP -p icmp -m icmp --icmp-type 8 -m limit --limit 4/sec -j ACCEPT > COMMIT > > I was able to create this simple ruleset out of a more complex firewall configuration. > This kernel oops appears on nine out of ten startups/reboots. > If it appears, iptables/nftables are not usable anymore. > For more details, consult kernel log. > > Steps to reproduce the kernel oops: > > # Install a fresh, minimal Debian 10 Buster system. (e.g. new VM) > $ apt update > $ apt install iptables iptables-persistent > # Save IPv4 rules on installation, do not save IPv6 rules. > $ cat << \EOF > /etc/iptables/rules.v4 > *filter > :INPUT ACCEPT [0:0] > :FORWARD DROP [0:0] > :OUTPUT ACCEPT [0:0] > :MY-ICMP - [0:0] > - -A INPUT -j MY-ICMP > - -A MY-ICMP -p icmp -m icmp --icmp-type 3 -j ACCEPT > - -A MY-ICMP -p icmp -m icmp --icmp-type 11 -j ACCEPT > - -A MY-ICMP -p icmp -m icmp --icmp-type 8 -m limit --limit 4/sec -j ACCEPT > COMMIT > EOF > $ reboot > > You may need to reboot a second or third time, if it does not appear > on the first startup. > > I was able to reproduce this on AMD64 using VirtualBox VM and a > cloud server provider. It may cause a broken firewall configuration > which leads to a security issue if you reboot without monitoring. Thanks for the reproducing instructions. This looks the same as the bug reported at https://bugzilla.kernel.org/show_bug.cgi?id=203681 which is #931330. This should be fixed in 5.2.6-1. But might need to check which commit(s) fix the issue and see they are already backported to the 4.19.x stable series as well. Regards, Salvatore
Back to linux.debian.kernel | Previous | Next — Next in thread | Find similar | Unroll thread
Bug#934168: linux-image-4.19.0-5-amd64: iptables-restore may result in NULL pointer dereference at nf_tables_newrule on startup Salvatore Bonaccorso <carnil@debian.org> - 2019-08-07 22:50 +0200 Processed: Re: Bug#934168: linux-image-4.19.0-5-amd64: iptables-restore may result in NULL pointer dereference at nf_tables_newrule on startup "Debian Bug Tracking System" <owner@bugs.debian.org> - 2019-08-07 22:50 +0200 Bug#934168: linux-image-4.19.0-5-amd64: iptables-restore may result in NULL pointer dereference at nf_tables_newrule on startup Salvatore Bonaccorso <carnil@debian.org> - 2019-08-19 22:40 +0200
csiph-web