Project

General

Profile

Actions

Security #6669

closed

ip defrag: re-assembly error in bsd policy

Added by Jason Ish 9 months ago. Updated 5 months ago.

Status:
Closed
Priority:
Normal
Assignee:
Target version:
Affected Versions:
Label:
Git IDs:

f1709ea551124e1a64fdc509993ad022ab27aa77

Severity:
MODERATE
Disclosure Date:

Description

Given a subsequent fragment that starts before an original fragment, and overlaps the beginning of the original fragment, Suricata has been preferring the data from the original fragment.

However, per the Novak-Sturges paper, the original fragment data should only be preferred if it has an offset <= to the new fragment.

Fix is to use the data from the new fragment if it has an offset less than the offset of the original fragment.

This is covered in the test bsd/peose/test9.


Subtasks 2 (0 open2 closed)

Security #6670: ip defrag: re-assembly error in bsd policy (6.0.x backport)ClosedJason IshActions
Security #6672: ip defrag: re-assembly error in bsd policy (7.0.x backport)ClosedJason IshActions
Actions #1

Updated by OISF Ticketbot 9 months ago

  • Subtask #6670 added
Actions #2

Updated by OISF Ticketbot 9 months ago

  • Label deleted (Needs backport to 6.0)
Actions #3

Updated by OISF Ticketbot 9 months ago

  • Subtask #6672 added
Actions #4

Updated by OISF Ticketbot 9 months ago

  • Label deleted (Needs backport to 7.0)
Actions #5

Updated by Jason Ish 9 months ago

  • Status changed from New to In Review
Actions #6

Updated by Jason Ish 6 months ago

  • Status changed from In Review to Resolved
Actions #7

Updated by Jason Ish 6 months ago

  • Status changed from Resolved to In Review
Actions #8

Updated by Victor Julien 6 months ago

  • CVE set to 2024-32867
Actions #9

Updated by Victor Julien 6 months ago

  • Status changed from In Review to Closed
  • Git IDs updated (diff)
Actions #11

Updated by Victor Julien 5 months ago

Credits: PhD thesis work from Lucas Aubard supervised by Johan Mazel, Gilles Guette and Pierre Chifflier

Actions

Also available in: Atom PDF