Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Red Hat 7: RHSA-2015-2315-01 Moderate: NetworkManager DoS Attack

red hat
Calendar Grey November 19, 2015
Scroller Redhat
Revised Ubuntu NetworkManagement components tackle vulnerabilities and boost operational capabilities. Discover details.
Updated NetworkManager packages that fix two security issues, several bugs, and add various enhancements are now available for Red Hat Enterprise Linux 7

Solution

Before applying this update, make sure all previously released errata relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

Summary

NetworkManager is a system network service that manages network devices and connections.
It was discovered that NetworkManager would set device MTUs based on MTU values received in IPv6 RAs (Router Advertisements), without sanity checking the MTU value first. A remote attacker could exploit this flaw to create a denial of service attack, by sending a specially crafted IPv6 RA packet to disturb IPv6 communication. (CVE-2015-0272)
A flaw was found in the way NetworkManager handled router advertisements. An unprivileged user on a local network could use IPv6 Neighbor Discovery ICMP to broadcast a non-route with a low hop limit, causing machines to lower the hop limit on existing IPv6 routes. If this limit is small enough, IPv6 packets would be dropped before reaching the final destination. (CVE-2015-2924)
The network-manager-applet and NetworkManager-libreswan packages have been upgraded to upstream versions 1.0.6, and provide a number of bug fixes and enhancements over the previous versions. (BZ#1177582, BZ#1243057)
Bugs:
* It was not previously possible to set the Wi-Fi band to the "a" or "bg" values to lock to a specific frequency band. NetworkManager has been fixed, and it now sets the wpa_supplicant's "freq_list" option correctly, which enables proper Wi-Fi band locking. (BZ#1254461)
* NetworkManager immediately failed activation of devices that did not have a carrier early in the boot process. The legacy network.service then reported activation failure. Now, NetworkManager has a grace period during which it waits for the carrier to appear. Devices that have a carrier down for a short time on system startup no longer cause the legacy network.service to fail. (BZ#1079353)
* NetworkManager brought down a team device if the teamd service managing it exited unexpectedly, and the team device was deactivated. Now, NetworkManager respawns the teamd instances that disappear and is able to recover from a teamd failure avoiding disruption of the team device operation. (BZ#1145988)
* NetworkManager did not send the FQDN DHCP option even if host name was set to FQDN. Consequently, Dynamic DNS (DDNS) setups failed to update the DNS records for clients running NetworkManager. Now, NetworkManager sends the FQDN option with DHCP requests, and the DHCP server is able to create DNS records for such clients. (BZ#1212597)
* The command-line client was not validating the vlan.flags property correctly, and a spurious warning message was displayed when the nmcli tool worked with VLAN connections. The validation routine has been fixed, and the warning message no longer appears. (BZ#1244048)
* NetworkManager did not propagate a media access control (MAC) address change from a bonding interface to a VLAN interface on top of it. Consequently, a VLAN interface on top of a bond used an incorrect MAC address. Now, NetworkManager synchronizes the addresses correctly. (BZ#1264322)
Enhancements:
* IPv6 Privacy extensions are now enabled by default. NetworkManager checks the per-network configuration files, NetworkManager.conf, and then falls back to "/proc/sys/net/ipv6/conf/default/use_tempaddr" to determine and set IPv6 privacy settings at device activation. (BZ#1187525)
* The NetworkManager command-line tool, nmcli, now allows setting the wake-on-lan property to 0 ("none", "disable", "disabled"). (BZ#1260584)
* NetworkManager now provides information about metered connections. (BZ#1200452)
* NetworkManager daemon and the connection editor now support setting the Maximum Transmission Unit (MTU) of a bond. It is now possible to change MTU of a bond interface in a GUI. (BZ#1177582, BZ#1177860)
* NetworkManager daemon and the connection editor now support setting the MTU of a team, allowing to change MTU of a teaming interface. (BZ#1255927)
NetworkManager users are advised to upgrade to these updated packages, which correct these issues and add these enhancements.

References

https://access.redhat.com/security/cve/CVE-2015-0272 https://access.redhat.com/security/cve/CVE-2015-2924 https://access.redhat.com/security/updates/classification/#moderate

Package List

Red Hat Enterprise Linux Client (v. 7):
Source: ModemManager-1.1.0-8.git20130913.el7.src.rpm NetworkManager-1.0.6-27.el7.src.rpm NetworkManager-libreswan-1.0.6-3.el7.src.rpm network-manager-applet-1.0.6-2.el7.src.rpm
x86_64: ModemManager-1.1.0-8.git20130913.el7.x86_64.rpm ModemManager-debuginfo-1.1.0-8.git20130913.el7.i686.rpm ModemManager-debuginfo-1.1.0-8.git20130913.el7.x86_64.rpm ModemManager-glib-1.1.0-8.git20130913.el7.i686.rpm ModemManager-glib-1.1.0-8.git20130913.el7.x86_64.rpm NetworkManager-1.0.6-27.el7.x86_64.rpm NetworkManager-adsl-1.0.6-27.el7.x86_64.rpm NetworkManager-bluetooth-1.0.6-27.el7.x86_64.rpm NetworkManager-debuginfo-1.0.6-27.el7.i686.rpm NetworkManager-debuginfo-1.0.6-27.el7.x86_64.rpm NetworkManager-glib-1.0.6-27.el7.i686.rpm NetworkManager-glib-1.0.6-27.el7.x86_64.rpm NetworkManager-libnm-1.0.6-27.el7.i686.rpm NetworkManager-libnm-1.0.6-27.el7.x86_64.rpm NetworkManager-libreswan-1.0.6-3.el7.x86_64.rpm NetworkManager-libreswan-debuginfo-1.0.6-3.el7.x86_64.rpm NetworkManager-libreswan-gnome-1.0.6-3.el7.x86_64.rpm NetworkManager-team-1.0.6-27.el7.x86_64.rpm NetworkManager-tui-1.0.6-27.el7.x86_64.rpm NetworkManager-wifi-1.0.6-27.el7.x86_64.rpm NetworkManager-wwan-1.0.6-27.el7.x86_64.rpm libnm-gtk-1.0.6-2.el7.i686.rpm

Read the Full Advisory


Advisory ID: RHSA-2015:2315-01
Product: Red Hat Enterprise Linux
Issue date: 2015-11-19

Topic

Updated NetworkManager packages that fix two security issues, several bugs,and add various enhancements are now available for Red Hat EnterpriseLinux 7.Red Hat Product Security has rated this update as having Moderate securityimpact. Common Vulnerability Scoring System (CVSS) base scores, which givedetailed severity ratings, are available for each vulnerability from theCVE links in the References section.

Relevant Releases Architectures

Red Hat Enterprise Linux Client (v. 7) - x86_64

Red Hat Enterprise Linux Client Optional (v. 7) - x86_64

Red Hat Enterprise Linux ComputeNode (v. 7) - x86_64

Red Hat Enterprise Linux ComputeNode Optional (v. 7) - x86_64

Red Hat Enterprise Linux Server (v. 7) - aarch64, ppc64, ppc64le, s390x, x86_64

Red Hat Enterprise Linux Server Optional (v. 7) - aarch64, ppc64, ppc64le, s390x, x86_64

Red Hat Enterprise Linux Workstation (v. 7) - x86_64

Red Hat Enterprise Linux Workstation Optional (v. 7) - x86_64

Bugs Fixed

918692 - PIN/Password dialog for Mobile Broadband forces user to enter password, even if it's not needed

1062301 - NetworkManager should provide a way to reload a configuration and to refresh resolv.conf if necessary

1139536 - [RFE] Improve handling of DEVICE and HWADDR in nm-connection-editor

1141417 - Persistent wake on lan across reboot

1168388 - veth device goes down when ipv4 dhcp lease expires

1168657 - nmcli hangs when deleting profile two times

1182575 - [nmcli] Can't add certificate blob via nmcli as description states

1183015 - ipv6.method shared prevents connection from being upped

1183444 - Attaching a team device to a bridge doesn't work.

1187525 - Enable privacy extensions by default

1192132 - CVE-2015-0272 kernel/NetworkManager: remote DoS using IPv6 RA with bogus MTU

1200451 - feature request: Indicate 2ghz and 5ghz wifi device capabilities

1200452 - feature request: provide information about metered connections

1201497 - [PATCH] fix a configure-and-quit=yes bug when DHCP client ID is set and hostname is not given

1207730 - Continuous IPv6 router solicitation loop

1209902 - CVE-2015-2924 NetworkManager: denial of service (DoS) attack against IPv6 network stacks due to improper handling of Router Advertisements

1211133 - high cpu use with many IPv6 cloned routes

1211859 - _nl_get_vtable: assertion 'vtable.handle' failed

1229471 - [bluez5] add DUN support to nm-connection-editor

1238840 - libreswan vpn is not working

Read the Full Advisory

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.