EtherLeak: ICMP Kernel Memory Disclosure via Ethernet Padding | CVE-2003-0001 & CVE-2021-3031

EtherLeak is an ICMP information disclosure class that resurfaces across vendors and decades — same root cause, different hardware. IP stacks that trust IP_Total_Length over actual frame length expose NIC DMA ring buffer contents via ICMP Echo. Combined with TTL=0, extraction runs at 1,800 bytes/second with zero IDS alerts, zero firewall logs. Covers full mechanism, threshold math, Suricata detection rules, and Scapy PoC.

June 5, 2026 · 9 min · JM00NJ
EtherLeak: ICMP Kernel Memory Disclosure via Ethernet Padding | CVE-2003-0001 & CVE-2021-3031

ArubaOS 8.13.2.0 Pre-Auth ICMP Buffer Over-read: EtherLeak via TTL=0 + IP Total Length | HPE Bugcrowd

Three compounding weaknesses in ArubaOS 8.13.2.0 ICMP handler: IP Total Length over-read reads 18 bytes past actual frame data into Ethernet padding (CWE-126); TTL=0 packets are processed and replied to in RFC 791 violation (CWE-1284); ICMP checksums are never validated (CWE-354). TTL=0 makes extraction invisible — routers don’t forward, IDS ignores, firewalls don’t log. 27/27 crafted probes confirmed. On physical AOS-8 hardware with active management traffic, the 18-byte DMA region contains previous frame fragments. CVE-2003-0001 and CVE-2021-3031 accepted on identical mechanism without physical hardware PoC.

June 1, 2026 · 4 min · JM00NJ
ArubaOS 8.13.2.0 Pre-Auth ICMP Buffer Over-read: EtherLeak via TTL=0 + IP Total Length | HPE Bugcrowd
DigitalOcean Referral Badge