Linux panic on fragemented IPv6 traffic (icmp6_send)
seclists.org
seclists.org
This all happened December 8th. I'm surprised this didn't make more noise, but it's unclear to me what versions are affected. It was reported on 4.8.12 and not marked as a regression, and was fixed during 4.9 development.
Presuming this landed in 4.8 (guessing based on the kernels Debian listed fixes for versus not affected [1]), which came out in October 2016, that's 2 months of time when someone could have picked a stable release and gotten bitten by this.
update: it's actually even narrower, since it looks like those lines were added in a patch from November 3rd [2], so maybe a month.
[1] - https://security-tracker.debian.org/tracker/CVE-2016-9919
Are there not static analysis tools routinely used against Linux that should have caught this?
Or runtime memory access detection, like valgrind.
I know both might be slow on a project the size the Linux kernel, but it seems worth it.
But today, it's impossible:
http://marc.info/?l=user-mode-linux-user&m=140187124116532&w...
> > So, is it possible to run linux (>3.12) with valgrind? If yes, how to do it?
> No.
> A long time ago it was possible after applying a patch to both UML and valgrind.