Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Red Hat: RHSA-2016:1086-01 Moderate: libndp Man-In-The-Middle Issue

red hat
Calendar Grey May 17, 2016
Scroller Redhat
An essential libndp security patch for Red Hat Enterprise Linux tackles risks linked to internet-based threats.
An update for libndp is now available for Red Hat Enterprise Linux 7

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

After installing this update, all running applications using libndp (for example, Network Manager) must be restarted for this update to take effect.

Summary

Libndp is a library (used by NetworkManager) that provides a wrapper for the IPv6 Neighbor Discovery Protocol. It also provides a tool named ndptool for sending and receiving NDP messages.
Security Fix(es):
* It was found that libndp did not properly validate and check the origin of Neighbor Discovery Protocol (NDP) messages. An attacker on a non-local network could use this flaw to advertise a node as a router, allowing them to perform man-in-the-middle attacks on a connecting client, or disrupt the network connectivity of that client. (CVE-2016-3698)
Red Hat would like to thank Julien Bernard (Viagénie) for reporting this issue.

References

https://access.redhat.com/security/cve/CVE-2016-3698 https://access.redhat.com/security/updates/classification/#moderate

Package List

Red Hat Enterprise Linux Client (v. 7):
Source: libndp-1.2-6.el7_2.src.rpm
x86_64: libndp-1.2-6.el7_2.i686.rpm libndp-1.2-6.el7_2.x86_64.rpm libndp-debuginfo-1.2-6.el7_2.i686.rpm libndp-debuginfo-1.2-6.el7_2.x86_64.rpm
Red Hat Enterprise Linux Client Optional (v. 7):
x86_64: libndp-debuginfo-1.2-6.el7_2.i686.rpm libndp-debuginfo-1.2-6.el7_2.x86_64.rpm libndp-devel-1.2-6.el7_2.i686.rpm libndp-devel-1.2-6.el7_2.x86_64.rpm
Red Hat Enterprise Linux ComputeNode (v. 7):
Source: libndp-1.2-6.el7_2.src.rpm
x86_64: libndp-1.2-6.el7_2.i686.rpm libndp-1.2-6.el7_2.x86_64.rpm libndp-debuginfo-1.2-6.el7_2.i686.rpm libndp-debuginfo-1.2-6.el7_2.x86_64.rpm
Red Hat Enterprise Linux ComputeNode Optional (v. 7):
x86_64: libndp-debuginfo-1.2-6.el7_2.i686.rpm libndp-debuginfo-1.2-6.el7_2.x86_64.rpm libndp-devel-1.2-6.el7_2.i686.rpm libndp-devel-1.2-6.el7_2.x86_64.rpm
Red Hat Enterprise Linux Server (v. 7):
Source: libndp-1.2-6.el7_2.src.rpm
ppc64: libndp-1.2-6.el7_2.ppc.rpm libndp-1.2-6.el7_2.ppc64.rpm libndp-debuginfo-1.2-6.el7_2.ppc.rpm libndp-debuginfo-1.2-6.el7_2.ppc64.rpm
ppc64le: libndp-1.2-6.el7_2.ppc64le.rpm libndp-debuginfo-1.2-6.el7_2.ppc64le.rpm
s390x: libndp-1.2-6.el7_2.s390.rpm libndp-1.2-6.el7_2.s390x.rpm libndp-debuginfo-1.2-6.el7_2.s390.rpm libndp-debuginfo-1.2-6.el7_2.s390x.rpm


Read the Full Advisory


Advisory ID: RHSA-2016:1086-01
Product: Red Hat Enterprise Linux
Issue date: 2016-05-17

Topic

An update for libndp is now available for Red Hat Enterprise Linux 7.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.

Relevant Releases Architectures

Red Hat Enterprise Linux Client (v. 7) - x86_64

Red Hat Enterprise Linux Client Optional (v. 7) - x86_64

Red Hat Enterprise Linux ComputeNode (v. 7) - x86_64

Red Hat Enterprise Linux ComputeNode Optional (v. 7) - x86_64

Red Hat Enterprise Linux Server (v. 7) - ppc64, ppc64le, s390x, x86_64

Red Hat Enterprise Linux Server Optional (v. 7) - ppc64, ppc64le, s390x, x86_64

Red Hat Enterprise Linux Workstation (v. 7) - x86_64

Red Hat Enterprise Linux Workstation Optional (v. 7) - x86_64

Bugs Fixed

1329366 - CVE-2016-3698 libndp: denial of service due to insufficient validation of source of NDP messages

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.