SB2024062076 - Improper locking in Linux kernel netlink
Published: June 20, 2024 Updated: May 13, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper locking (CVE-ID: CVE-2021-47606)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper locking within the netlink_sendmsg() function in net/netlink/af_netlink.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/c54a60c8fbaa774f828e26df79f66229a8a0e010
- https://git.kernel.org/stable/c/40cf2e058832d9cfaae98dfd77334926275598b6
- https://git.kernel.org/stable/c/54e785f7d5c197bc06dbb8053700df7e2a093ced
- https://git.kernel.org/stable/c/ff3f517bf7138e01a17369042908a3f345c0ee41
- https://git.kernel.org/stable/c/c0315e93552e0d840e9edc6abd71c7db82ec8f51
- https://git.kernel.org/stable/c/dadce61247c6230489527cc5e343b6002d1114c5
- https://git.kernel.org/stable/c/4c986072a8c9249b9398c7a18f216dc26a9f0e35
- https://git.kernel.org/stable/c/f123cffdd8fe8ea6c7fded4b88516a42798797d0
- https://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.259
- https://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.222
- https://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.296
- https://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.294
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.87
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.10
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.16
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.167