[0] Discussion: https://old.reddit.com/r/netsec/comments/11s80zo/cve20232341...
[1] Advisory: https://msrc.microsoft.com/update-guide/vulnerability/CVE-20...
Reading the words I do understand, the raw socket aspect seems to be irrelevant right? The vulnerable code would be the the parser that incorrectly runs code based on invalid input? It might require raw socket to trigger the vulnerability, but perhaps it would not exist if it was not written in kernel C but rather in user space garbage collected code with a good type system (not sure what the vulnerability actually is).
TAPIF=tap0; BR=br0; LOCAL_IP=192.whatever; MASK=24; REAL_IP=eth0
sudo ip tuntap add dev $TAPIF mode tap user $(whoami)
sudo ip addr add $LOCAL_IP/$MASK dev $TAPIF
sudo ip link set $TAPIF up
sudo ip link add $BR type bridge
sudo ip link set $TAPIF master $BR
sudo ip link set $REAL_IF up
sudo ip link set $REAL_IF master $BR
Means you don't have to add iptables rules to get the kernel tcp/ip stack to ignore packets meant for your program specific user level stack. Raw sockets require special permissions. sudo setcap cap_net_admin,cap_net_raw=eip my_prog_bin
ping needs this, for example. getcap $(which ping)
/bin/ping = cap_net_raw+ep
But this underscores the real issue we face because enough people won't care about your security if its convenient for their programming that it isn't a barrier to acceptance.You have to get the kernel to do things, probably using root privs, to get out of the way of your programs ip traffic now. The kernel will jump in and reject a syn or synack response meant for your program and its user level stack. You don't have do anything like that if your program calls socket() to get an fd and goes on in the usual manner from there.
For example normally you will get permission denied when you try to listen on sub-1024 port on normal user.
I'd also imagine if kernel is doing any kind of connection tracking (so really anything with firewall), it would be more optimal to have that connection tracked in kernel vs decoding it and adding to conntrack table.
I guess some kind of half-RAW could be done in place, like say a socket where you define protocol and port but handle actual packets in userspace ?