LWN.net Logo

librdmacm: bogus address resolution

Package(s):librdmacm CVE #(s):CVE-2012-4516
Created:December 17, 2012 Updated:December 19, 2012
Description: From the Red Hat bugzilla:

A security flaw was found in the way librdmacm, a userspace RDMA Communication Managment API allowing to specify connections using TCP/IP addresses even though it opens RDMA specific connections, performed binding to the underlying ib_acm service (librdmacm used default port value of 6125 to bind to ib_acm service). An attacker able to run a rogue ib_acm service could use this flaw to make librdmacm applications to use potentially bogus address resolution information.

Alerts:
Fedora FEDORA-2012-19892 2012-12-15

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds