All of lore.kernel.org
 help / color / mirror / Atom feed
From: Paul Barker <paul@pbarker.dev>
To: Junjie Cao <junjie.cao@linux.dev>,
	 openembedded-core@lists.openembedded.org
Subject: Re: [OE-core][PATCH v3 1/9] cve-exclusions: set status for CVE-2019-14899
Date: Sun, 16 Aug 2026 16:50:39 +0100	[thread overview]
Message-ID: <5349c5a65816faec9fdc46092e46a13816a32a70.camel@pbarker.dev> (raw)
In-Reply-To: <20260812072842.1176341-2-junjie.cao@linux.dev>

On Wed, 2026-08-12 at 02:28 -0500, Junjie Cao wrote:
> A network-adjacent attacker can send packets addressed to a host's VPN
> tunnel address over the physical interface. Because Linux uses the weak
> host model by default, the host replies, which lets the attacker infer
> the tunnel address, confirm active connections and eventually inject
> into the tunneled TCP stream.
> 
> No upstream kernel fix exists. The disclosure notes that reverse path
> filtering is not a complete solution because the attack also works over
> IPv6, which has no rp_filter; the mitigation that shipped was a firewall
> rule added to wg-quick(8) in userspace:

We should drop the discussion of mitigations here - none of them are
complete mitigations and there are more nuances.

> 
>   https://www.openwall.com/lists/oss-security/2019/12/05/1
>   https://lore.kernel.org/all/20191205191318.GA44156@zx2c4.com/
> 
> Distribution trackers record the same state: Ubuntu has it deferred
> since 2019-12-13, Debian does not track it against the kernel, and Red
> Hat scopes it to openvpn:
> 
>   https://ubuntu.com/security/CVE-2019-14899
>   https://security-tracker.debian.org/tracker/CVE-2019-14899
> 
> Record it unpatched so it stays visible rather than excluded.
> 
> CC: Paul Barker <paul@pbarker.dev>
> AI-Generated: Uses Claude (claude-opus-5)
> Signed-off-by: Junjie Cao <junjie.cao@linux.dev>
> ---
> v3:
> - use "unpatched" instead of "upstream-wontfix": there is no upstream
>   statement, only distribution and disclosure sources
> 
> v2: https://lore.kernel.org/openembedded-core/20260803084827.1348810-1-junjie.cao@linux.dev/
> 
>  meta/recipes-kernel/linux/cve-exclusion.inc | 7 +++++++
>  1 file changed, 7 insertions(+)
> 
> diff --git a/meta/recipes-kernel/linux/cve-exclusion.inc b/meta/recipes-kernel/linux/cve-exclusion.inc
> index d27d764..5ed4a00 100644
> --- a/meta/recipes-kernel/linux/cve-exclusion.inc
> +++ b/meta/recipes-kernel/linux/cve-exclusion.inc
> @@ -192,3 +192,10 @@ CVE_STATUS[CVE-2025-68195] = "fixed-version: Fixed from 6.18"
>  # Fix https://git.kernel.org/stable/c/b4b64fda4d30a83a7f00e92a0c8a1d47699609f3
>  # Backport https://git.kernel.org/stable/c/75c5d9bce072abbbc09b701a49869ac23c34a906
>  CVE_STATUS[CVE-2025-71145] = "cpe-stable-backport: Fixed from v6.18.3"
> +
> +# Consequence of the default weak host model, not a specific defect;
> +# mitigation is firewall configuration only (rp_filter for IPv4, a
> +# strong host model rule such as wg-quick(8)'s, which also covers IPv6).
> +# https://ubuntu.com/security/CVE-2019-14899
> +CVE_STATUS[CVE-2019-14899] = "unpatched: consequence of the default weak \
> +host model, no upstream kernel fix, mitigated by firewall configuration"

I recommend slightly different wording. Include the triage date, drop
discussion of mitigation.

    # Triaged August 2026 - no upstream fix, Ubuntu fix deferred
    # https://ubuntu.com/security/CVE-2019-14899
    CVE_STATUS[CVE-2019-14899] = "unpatched: Consequence of the default weak host \
    model, no upstream fix"

Best regards,

-- 
Paul Barker



  reply	other threads:[~2026-08-16 15:50 UTC|newest]

Thread overview: 22+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-12  7:28 [OE-core][PATCH v3 0/9] cve-exclusions: triage nine kernel CVEs lacking upstream fix data Junjie Cao
2026-08-12  7:28 ` [OE-core][PATCH v3 1/9] cve-exclusions: set status for CVE-2019-14899 Junjie Cao
2026-08-16 15:50   ` Paul Barker [this message]
2026-08-12  7:28 ` [OE-core][PATCH v3 2/9] cve-exclusions: set status for CVE-2021-3714 Junjie Cao
2026-08-16 15:53   ` Paul Barker
2026-08-12  7:28 ` [OE-core][PATCH v3 3/9] cve-exclusions: set status for CVE-2021-3864 Junjie Cao
2026-08-16 15:55   ` Paul Barker
2026-08-12  7:28 ` [OE-core][PATCH v3 4/9] cve-exclusions: set status for CVE-2022-0400 Junjie Cao
2026-08-16 16:35   ` Paul Barker
2026-08-12  7:28 ` [OE-core][PATCH v3 5/9] cve-exclusions: set status for CVE-2022-1247 Junjie Cao
2026-08-16 16:21   ` Paul Barker
2026-08-12  7:28 ` [OE-core][PATCH v3 6/9] cve-exclusions: set status for CVE-2022-4543 Junjie Cao
2026-08-16 16:00   ` Paul Barker
2026-08-12  7:28 ` [OE-core][PATCH v3 7/9] cve-exclusions: set status for CVE-2023-3397 Junjie Cao
2026-08-16 16:05   ` Paul Barker
2026-08-12  7:28 ` [OE-core][PATCH v3 8/9] cve-exclusions: set status for CVE-2023-6238 Junjie Cao
2026-08-16 16:11   ` Paul Barker
2026-08-12  7:28 ` [OE-core][PATCH v3 9/9] cve-exclusions: set status for CVE-2023-6240 Junjie Cao
2026-08-16 16:14   ` Paul Barker
2026-08-16 16:39 ` [OE-core][PATCH v3 0/9] cve-exclusions: triage nine kernel CVEs lacking upstream fix data Paul Barker
2026-08-19 10:43   ` Junjie Cao
2026-08-24  4:13     ` Junjie Cao

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=5349c5a65816faec9fdc46092e46a13816a32a70.camel@pbarker.dev \
    --to=paul@pbarker.dev \
    --cc=junjie.cao@linux.dev \
    --cc=openembedded-core@lists.openembedded.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.