kernel panic [linux 2.2.19-7] on UDP scan CP4.1-SP5

From: Yanek Korff (yanek@cigital.com)
Date: 11/14/01


Message-ID: <4BC10D47D7ACD3119FA800104B1F8836013A4F06@exchange.cigital.com>
From: Yanek Korff <yanek@cigital.com>
To: "'vuln-dev@securityfocus.com'" <vuln-dev@securityfocus.com>
Subject: kernel panic [linux 2.2.19-7] on UDP scan CP4.1-SP5
Date: Wed, 14 Nov 2001 08:40:24 -0500

I'm testing out CP4.1 SP5 on Linux RH7.0. I seem to have gotten everything
configured the way I want it and am starting to run some scans to see what I
can see. Well, what I see is: nmap -sU -P0 ip_addr causes the machine to
instantly crash with a kernel panic, or in some cases, reboot. I'm not
great at troubleshooting kernel/module troubles so any help would be greatly
appreciated. IF you happen to have a Linux CP FW-1 box you could run nmap
against, I'd love to know your results (incl OS/kernel info). Might want to
do this off-hours, though.

Without CP-FW1 running (/etc/rc.d/init.d/firewall1 stop), I cannot cause a
kernel panic with a UDP scan. Has anyone else noticed this behavior?

Hardware:
Dell Dimension XPSB800r
128MB RAM
3Com EtherLink III 3c905-TX (three of them)

Have been able to reproduce this problem with kernels:
2.2.19-7 (CUSTOM)
2.2.16-20 (GENERIC RH 7.0)

Tail end of the error message (after register & stack dump):
Code: 8b 41 08 3d 2b 2f c3 a5 0f 85 c6 00 00 00 8b 41 0c 85 c0 74
Aiee, killing interrupt handler
Kernel panic: Attempted to kill the idle task!
In swapper task - not syncing

-Yanek.



Relevant Pages

  • Re: Samba Network
    ... only samba and may stay this way for a time. ... I can write from a linux box accross ... 100000 2 tcp 111 portmapper ... 100000 2 udp 111 portmapper ...
    (alt.os.linux.suse)
  • Re: Identifying Kernel 2.4.x based Linux machines using UDP
    ... > Linux Kernel 2.4.x has a bug with the UDP implementation which allows ... It also isn't specific to UDP -- you'll find ... Last year I added a feature to Nmap which automates this IPID ...
    (Bugtraq)
  • Re: NFS tuning on FreeBSD
    ... If I recall your original question properly your server was FreeBSD and your client was Linux. ... From FreeBSD the only way that I have found was to embed the options into the fstab file and use the short version of the mount command when attaching the filesystem. ... The documentation on my Ubuntu box indicates that it's Linux client defaults to NFSv2 and uses UDP. ... The behavior that I would expect to see from an Ubuntu Linux NFS client with a FreeBSD NFS server would be a NFSv2 UDP mount. ...
    (freebsd-questions)
  • Re: Identifying Kernel 2.4.x based Linux machines using UDP
    ... On Linux you can "customize" the default ttl that will be used in all ... changing the ip_default_ttl on a standard kernel might do the ... attacker to fingerprint your os.... ... > The IP Identification field value with the UDP datagram is zero. ...
    (Bugtraq)
  • RE: problems receiving e-mail to my server redux
    ... > I'm not familiar with the configuration of a Linksys ... > to indicate that incoming connections using TCP, UDP, or both ... > are activated once you enter a port number in the field." ... I installed BIND on my Linux box and set it up to start at every ...
    (RedHat)

Loading