HIGH Public exploit
net UFO Path Switch Overflow
CVE-2017-1000112
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
KernelScan AI7.0HIGH
01Description
Linux kernel: Exploitable memory corruption due to UFO to non-UFO path switch. When building a UFO packet with MSG_MORE __ip_append_data() calls ip_ufo_append_data() to append. However in between two send() calls, the append path can be switched from UFO to non-UFO one, which leads to a memory corruption. In case UFO packet lengths exceeds MTU, copy = maxfraglen - skb->len becomes negative on the non-UFO path and the branch to allocate new skb is taken. This triggers fragmentation and computation of fraggap = skb_prev->len - maxfraglen. Fraggap can exceed MTU, causing copy = datalen - transhdrlen - fraggap to become negative. Subsequently skb_copy_and_csum_bits() writes out-of-bounds. A similar issue is present in IPv6 code. The bug was introduced in e89e9cf539a2 ("[IPv4/IPv6]: UFO Scatter-gather approach") on Oct 18 2005.
02KernelScan AI Analysis
Risk summary
A local unprivileged user can trigger memory corruption via the UDP stack by switching between UFO and non-UFO paths during fragmented sends.
Vulnerability analysis
When a UDP socket uses UDP Fragmentation Offload (UFO) with MSG_MORE, the kernel appends data to a single large packet. If a subsequent send() call on the same socket takes the non-UFO path (e.g., because the packet exceeds MTU or device features change), the code miscalculates lengths and writes data out-of-bounds. The fix ensures the path cannot switch between UFO and non-UFO mid-stream, preventing the length underflow. This is exploitable by any local unprivileged user with network access.
Exploit availability
KernelScan found public exploit code for this CVE. Open it in the CVE browser to see what we found, where, and how strong the evidence is — that needs a free account with a confirmed email address.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 3.10 | — | 3.10.108 | — |
| 3.16 | — | 3.16.47 | — |
| 3.18 | — | 3.18.65 | — |
| 4.4 | — | 4.4.82 | — |
| 4.9 | — | 4.9.43 | — |
| 4.12 | — | 4.12.7 | — |
| mainline | — | 2.6.15-rc1 | e89e9cf539a2 |