What's new

Talos Vulnerability

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

AP3

Occasional Visitor
Hi All,

This morning I noticed some strange log entries:

Code:
Jan 13 04:37:58 kernel: pgd = ffffffc015173000
Jan 13 04:37:58 kernel: [00000020] *pgd=0000000015175003, *pud=0000000015175003, *pmd=000000001516e003, *pte=0000000000000000
Jan 13 04:37:58 kernel: CPU: 1 PID: 13996 Comm: cfg_server Tainted: P           O    4.1.27 #2
Jan 13 04:37:58 kernel: Hardware name: Broadcom-v8A (DT)
Jan 13 04:37:58 kernel: task: ffffffc01e02ebc0 ti: ffffffc013e2c000 task.ti: ffffffc013e2c000
Jan 13 04:37:58 kernel: PC is at 0x2f190
Jan 13 04:37:58 kernel: LR is at 0x2f160
Jan 13 04:37:58 kernel: pc : [<000000000002f190>] lr : [<000000000002f160>] pstate: 800d0010
Jan 13 04:37:58 kernel: sp : 00000000f6e6ec30
Jan 13 04:37:58 kernel: x12: 00000000000b5e1c
Jan 13 04:37:58 kernel: x11: 00000000f6c145e0 x10: 00000000f6c013e8
Jan 13 04:37:58 kernel: x9 : 00000000f6e6ee60 x8 : 0000000000000000
Jan 13 04:37:58 kernel: x7 : 000000000000000d x6 : 00000000f76ecce0
Jan 13 04:37:58 kernel: x5 : 00000000f76ecce0 x4 : 00000000f6c18c40
Jan 13 04:37:58 kernel: x3 : 000000000009db83 x2 : 0000000000000000
Jan 13 04:37:58 kernel: x1 : 00000000f6c08a08 x0 : 0000000000000000
Jan 13 04:37:58 kernel: CPU: 1 PID: 13996 Comm: cfg_server Tainted: P           O    4.1.27 #2
Jan 13 04:37:58 kernel: Hardware name: Broadcom-v8A (DT)
Jan 13 04:37:58 kernel: task: ffffffc01e02ebc0 ti: ffffffc013e2c000 task.ti: ffffffc013e2c000
Jan 13 04:37:58 kernel: PC is at 0x2f190
Jan 13 04:37:58 kernel: LR is at 0x2f160
Jan 13 04:37:58 kernel: pc : [<000000000002f190>] lr : [<000000000002f160>] pstate: 800d0010
Jan 13 04:37:58 kernel: sp : 00000000f6e6ec30
Jan 13 04:37:58 kernel: x12: 00000000000b5e1c
Jan 13 04:37:58 kernel: x11: 00000000f6c145e0 x10: 00000000f6c013e8
Jan 13 04:37:58 kernel: x9 : 00000000f6e6ee60 x8 : 0000000000000000
Jan 13 04:37:58 kernel: x7 : 000000000000000d x6 : 00000000f76ecce0
Jan 13 04:37:58 kernel: x5 : 00000000f76ecce0 x4 : 00000000f6c18c40
Jan 13 04:37:58 kernel: x3 : 000000000009db83 x2 : 0000000000000000
Jan 13 04:37:58 kernel: x1 : 00000000f6c08a08 x0 : 0000000000000000
Jan 13 04:38:17 rc_service: watchdog 1990:notify_rc start_cfgsync

It looks like a DoS vulnerability as documented here: https://talosintelligence.com/vulnerability_reports/TALOS-2022-1592

Apparently this was patched in Nov 22 by Asus.

I'm running 386.9 on an RT-AC86U - Should this patch have been included?
 
It looks like a DoS vulnerability
That's just the daemon that handles config syncing between AiMesh nodes crashing, there is nothing there to indicate this is related to any security issue.
 

Latest threads

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top