Upstream information

CVE-2015-8787 at MITRE

Description

The nf_nat_redirect_ipv4 function in net/netfilter/nf_nat_redirect.c in the Linux kernel before 4.4 allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by sending certain IPv4 packets to an incompletely configured interface, a related issue to CVE-2003-1604.

SUSE information

Overall state of this security issue: Does not affect SUSE products

This issue is currently rated as having moderate severity.

CVSS v2 Scores
  National Vulnerability Database SUSE
Base Score 10 5.4
Vector AV:N/AC:L/Au:N/C:C/I:C/A:C AV:N/AC:H/Au:N/C:N/I:N/A:C
Access Vector Network Network
Access Complexity Low High
Authentication None None
Confidentiality Impact Complete None
Integrity Impact Complete None
Availability Impact Complete Complete
SUSE Bugzilla entry: 963931 [RESOLVED / FIXED]

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
openSUSE Leap 42.1
  • drbd >= 8.4.6-8.1
  • drbd-debugsource >= 8.4.6-8.1
  • drbd-kmp-default >= 8.4.6_k4.1.31_30-8.1
  • drbd-kmp-default-debuginfo >= 8.4.6_k4.1.31_30-8.1
  • drbd-kmp-pv >= 8.4.6_k4.1.31_30-8.1
  • drbd-kmp-pv-debuginfo >= 8.4.6_k4.1.31_30-8.1
  • drbd-kmp-xen >= 8.4.6_k4.1.31_30-8.1
  • drbd-kmp-xen-debuginfo >= 8.4.6_k4.1.31_30-8.1
  • hdjmod >= 1.28-24.1
  • hdjmod-debugsource >= 1.28-24.1
  • hdjmod-kmp-default >= 1.28_k4.1.31_30-24.1
  • hdjmod-kmp-default-debuginfo >= 1.28_k4.1.31_30-24.1
  • hdjmod-kmp-pae >= 1.28_k4.1.31_30-24.1
  • hdjmod-kmp-pae-debuginfo >= 1.28_k4.1.31_30-24.1
  • hdjmod-kmp-pv >= 1.28_k4.1.31_30-24.1
  • hdjmod-kmp-pv-debuginfo >= 1.28_k4.1.31_30-24.1
  • hdjmod-kmp-xen >= 1.28_k4.1.31_30-24.1
  • hdjmod-kmp-xen-debuginfo >= 1.28_k4.1.31_30-24.1
  • ipset >= 6.25.1-5.1
  • ipset-debuginfo >= 6.25.1-5.1
  • ipset-debugsource >= 6.25.1-5.1
  • ipset-devel >= 6.25.1-5.1
  • ipset-kmp-default >= 6.25.1_k4.1.31_30-5.1
  • ipset-kmp-default-debuginfo >= 6.25.1_k4.1.31_30-5.1
  • ipset-kmp-pae >= 6.25.1_k4.1.31_30-5.1
  • ipset-kmp-pae-debuginfo >= 6.25.1_k4.1.31_30-5.1
  • ipset-kmp-pv >= 6.25.1_k4.1.31_30-5.1
  • ipset-kmp-pv-debuginfo >= 6.25.1_k4.1.31_30-5.1
  • ipset-kmp-xen >= 6.25.1_k4.1.31_30-5.1
  • ipset-kmp-xen-debuginfo >= 6.25.1_k4.1.31_30-5.1
  • kernel-debug >= 4.1.31-30.2
  • kernel-debug-base >= 4.1.31-30.2
  • kernel-debug-base-debuginfo >= 4.1.31-30.2
  • kernel-debug-debuginfo >= 4.1.31-30.2
  • kernel-debug-debugsource >= 4.1.31-30.2
  • kernel-debug-devel >= 4.1.31-30.2
  • kernel-debug-devel-debuginfo >= 4.1.31-30.2
  • kernel-default >= 4.1.31-30.2
  • kernel-default-base >= 4.1.31-30.2
  • kernel-default-base-debuginfo >= 4.1.31-30.2
  • kernel-default-debuginfo >= 4.1.31-30.2
  • kernel-default-debugsource >= 4.1.31-30.2
  • kernel-default-devel >= 4.1.31-30.2
  • kernel-devel >= 4.1.31-30.1
  • kernel-docs >= 4.1.31-30.3
  • kernel-docs-html >= 4.1.31-30.3
  • kernel-docs-pdf >= 4.1.31-30.3
  • kernel-ec2 >= 4.1.31-30.2
  • kernel-ec2-base >= 4.1.31-30.2
  • kernel-ec2-base-debuginfo >= 4.1.31-30.2
  • kernel-ec2-debuginfo >= 4.1.31-30.2
  • kernel-ec2-debugsource >= 4.1.31-30.2
  • kernel-ec2-devel >= 4.1.31-30.2
  • kernel-macros >= 4.1.31-30.1
  • kernel-obs-build >= 4.1.31-30.3
  • kernel-obs-build-debugsource >= 4.1.31-30.3
  • kernel-obs-qa >= 4.1.31-30.1
  • kernel-obs-qa-xen >= 4.1.31-30.1
  • kernel-pae >= 4.1.31-30.2
  • kernel-pae-base >= 4.1.31-30.2
  • kernel-pae-base-debuginfo >= 4.1.31-30.2
  • kernel-pae-debuginfo >= 4.1.31-30.2
  • kernel-pae-debugsource >= 4.1.31-30.2
  • kernel-pae-devel >= 4.1.31-30.2
  • kernel-pv >= 4.1.31-30.2
  • kernel-pv-base >= 4.1.31-30.2
  • kernel-pv-base-debuginfo >= 4.1.31-30.2
  • kernel-pv-debuginfo >= 4.1.31-30.2
  • kernel-pv-debugsource >= 4.1.31-30.2
  • kernel-pv-devel >= 4.1.31-30.2
  • kernel-source >= 4.1.31-30.1
  • kernel-source-vanilla >= 4.1.31-30.1
  • kernel-syms >= 4.1.31-30.1
  • kernel-vanilla >= 4.1.31-30.2
  • kernel-vanilla-debuginfo >= 4.1.31-30.2
  • kernel-vanilla-debugsource >= 4.1.31-30.2
  • kernel-vanilla-devel >= 4.1.31-30.2
  • kernel-xen >= 4.1.31-30.2
  • kernel-xen-base >= 4.1.31-30.2
  • kernel-xen-base-debuginfo >= 4.1.31-30.2
  • kernel-xen-debuginfo >= 4.1.31-30.2
  • kernel-xen-debugsource >= 4.1.31-30.2
  • kernel-xen-devel >= 4.1.31-30.2
  • libipset3 >= 6.25.1-5.1
  • libipset3-debuginfo >= 6.25.1-5.1
  • lttng-modules >= 2.7.0-2.1
  • lttng-modules-debugsource >= 2.7.0-2.1
  • lttng-modules-kmp-default >= 2.7.0_k4.1.31_30-2.1
  • lttng-modules-kmp-default-debuginfo >= 2.7.0_k4.1.31_30-2.1
  • lttng-modules-kmp-pv >= 2.7.0_k4.1.31_30-2.1
  • lttng-modules-kmp-pv-debuginfo >= 2.7.0_k4.1.31_30-2.1
  • pcfclock >= 0.44-266.1
  • pcfclock-debuginfo >= 0.44-266.1
  • pcfclock-debugsource >= 0.44-266.1
  • pcfclock-kmp-default >= 0.44_k4.1.31_30-266.1
  • pcfclock-kmp-default-debuginfo >= 0.44_k4.1.31_30-266.1
  • pcfclock-kmp-pae >= 0.44_k4.1.31_30-266.1
  • pcfclock-kmp-pae-debuginfo >= 0.44_k4.1.31_30-266.1
  • pcfclock-kmp-pv >= 0.44_k4.1.31_30-266.1
  • pcfclock-kmp-pv-debuginfo >= 0.44_k4.1.31_30-266.1
  • vhba-kmp >= 20140928-5.1
  • vhba-kmp-debugsource >= 20140928-5.1
  • vhba-kmp-default >= 20140928_k4.1.31_30-5.1
  • vhba-kmp-default-debuginfo >= 20140928_k4.1.31_30-5.1
  • vhba-kmp-pae >= 20140928_k4.1.31_30-5.1
  • vhba-kmp-pae-debuginfo >= 20140928_k4.1.31_30-5.1
  • vhba-kmp-pv >= 20140928_k4.1.31_30-5.1
  • vhba-kmp-pv-debuginfo >= 20140928_k4.1.31_30-5.1
  • vhba-kmp-xen >= 20140928_k4.1.31_30-5.1
  • vhba-kmp-xen-debuginfo >= 20140928_k4.1.31_30-5.1
Patchnames:
openSUSE-2016-1076
openSUSE-2016-445