A vulnerability in the Linux kernel that allows for a crash via sending a UDP packet.

In the Linux kernel identified vulnerability (CVE-2019-11683), allowing a remote denial of service through the sending of specially crafted UDP packets (packet-of-death). The issue is caused by a flaw in the udp_gro_receive_segment handler (net/ipv4/udp_offload.c) related to the implementation of GRO (Generic Receive Offload) and may lead to corruption of kernel memory areas when processing UDP packets with zero payload (empty payload).

The issue affects only the kernel 5.0, as GRO support for UDP sockets was within introduced last November and made it into only the latest stable kernel release. The GRO technology allows for faster processing of a large number of incoming packets by aggregating several packets into larger blocks that do not require separate handling for each packet.
For TCP, the issue does not manifest, as packet aggregation without payload is not supported for this protocol.

The vulnerability has so far been patched only in the form of a patch, a corrective update has not yet been published (the fix did not make it into yesterday's 5.0.11 update ). The kernel 5.0 has made its way intoand other continuously updated distributions. Fedora 30, Ubuntu 19.04, Arch Linux, Gentoo Ubuntu 18.10 and earlier Debian, are not affected by the problem., RHEL/CentOS and Arch The problem was discovered as a result of

an automated fuzz testing system created by Google use cases and the analyzer syzbot KASAN (Kernel Address Sanitizer), aimed at identifying memory-related errors and cases of incorrect memory access, such as accesses to freed memory areas and placing code in memory areas not intended for such manipulations. A vulnerability has been identified in the Linux kernel (

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster