Memory leak in Linux kernel rds



Published: 2024-05-30
Risk Low
Patch available YES
Number of vulnerabilities 1
CVE-ID CVE-2021-47249
CWE-ID CWE-401
Exploitation vector Local
Public exploit N/A
Vulnerable software
Subscribe
Linux kernel
Operating systems & Components / Operating system

Vendor Linux Foundation

Security Bulletin

This security bulletin contains one low risk vulnerability.

1) Memory leak

EUVDB-ID: #VU89950

Risk: Low

CVSSv3.1: 4.8 [AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2021-47249

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to memory leak within the rds_recvmsg() function in net/rds/recv.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Install update from vendor's website.

Vulnerable software versions

Linux kernel: All versions

External links

http://git.kernel.org/stable/c/8c3ec88b03e9e4ca117dcdc4204fd3edcd02084f
http://git.kernel.org/stable/c/423c6939758fb3b9cf5abbd1e7792068a5c4ae8c
http://git.kernel.org/stable/c/1f79bc8ae81c05eb112a53f981cb2c244ee50d02
http://git.kernel.org/stable/c/06b7cb0194bd1ede0dd27f3a946e7c0279fba44a
http://git.kernel.org/stable/c/2038cd15eacdf7512755c27686822e0052eb9042
http://git.kernel.org/stable/c/5946fbf48355f5a8caeff72580c7658da5966b86
http://git.kernel.org/stable/c/b25b60d076164edb3025e85aabd2cf50a5215b91
http://git.kernel.org/stable/c/49bfcbfd989a8f1f23e705759a6bb099de2cff9f


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###