A vulnerability has been identified in the RDS protocol handler based on TCP (Reliable Datagram Socket, net/rds/tcp.c) (), which can lead to access to a previously freed memory area and denial of service (there is a possibility that this issue could be exploited to execute code). The problem is caused by a race condition that can arise during the execution of the rds_tcp_kill_sock function while clearing sockets for the network namespace.
In the specification , the issue is marked as remotely exploitable, but according to the description , a remote attack cannot be organized without local presence in the system and manipulation of namespaces. In particular, from the SUSE developers, the vulnerability is only exploited locally, and organizing an attack is quite complex and requires additional privileges in the system. While in the NVD the severity level is rated at 9.3 (CVSS v2) and 8.1 (CVSS v2), the SUSE rating assesses the danger at 6.4 out of 10.
Representatives from Ubuntu have also the severity of the issue as moderate. At the same time, according to the CVSS v3.0 specification, the problem is assigned a high attack complexity level with an exploitability score of only 2.2 out of 10.
According to from Cisco, the vulnerability is exploited remotely by sending TCP packets to active network services , and a prototype of the exploit already exists. It is unclear how accurate this information is; the report may only artistically present the assumptions from NVD. According to VulDB, an exploit has not yet been created, and the issue is only exploited locally.
The problem is present in kernels up to 5.0.8 and is blocked by the March , which is included in kernel 5.0.8. In most distributions, the issue remains unaddressed (, , , ). A fix has been released for SLE12 SP3, openSUSE 42.3, and .
Source: opennet.ru
