Executive Summary
The exploitation likelihood of this vulnerability is low, but the potential business impact is medium due to the potential for system crashes or unauthorized access. The vulnerability is in the Linux kernel, which is a critical component of many operating systems, making it a significant concern.
Enhanced Description
The fix for this vulnerability involves validating that each range start has a following element and that the following element is not itself marked as another range start. This ensures that the ports_match_v1() function correctly interprets the port range and prevents malformed rules from being created. The vulnerability has been resolved in the Linux kernel, and users are advised to update their systems to the latest version to ensure they are protected from this vulnerability.
Exploitation Context
An attacker could potentially exploit this vulnerability by creating a malformed firewall rule that would cause the Linux kernel to crash or behave unexpectedly. This could be used to disrupt the operation of a system or to gain unauthorized access. The attacker would need to have access to the system and be able to create firewall rules, which would typically require administrative privileges.
Patch Priority
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence in the severity ratings and exploitation likelihood is medium due to the limited information available about the vulnerability. However, the fact that the vulnerability is in the Linux kernel and has been resolved suggests that it is a significant concern.
In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_multiport: validate range encoding in checkentry ports_match_v1() treats any non-zero pflags entry as the start of a port range and unconditionally consumes the next ports[] element as the range end. The checkentry path currently validates protocol, flags and count, but it does not validate the range encoding itself. As a result, malformed rules can mark the last slot as a range start or place two range starts back to back, leaving ports_match_v1() to step past the last valid ports[] element while interpreting the rule. Reject malformed multiport v1 rules in checkentry by validating that each range start has a following element and that the following element is not itself marked as another range start.
1.8th percentile