SB20240621118 - Infinite loop in Linux kernel dsa
Published: June 21, 2024 Updated: May 13, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Infinite loop (CVE-ID: CVE-2021-47159)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to infinite loop within the dsa_master_get_strings() function in net/dsa/master.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0f2cb08c57edefb0e7b5045e0e3e9980a3d3aa37
- https://git.kernel.org/stable/c/ce5355f140a7987011388c7e30c4f8fbe180d3e8
- https://git.kernel.org/stable/c/caff86f85512b8e0d9830e8b8b0dfe13c68ce5b6
- https://git.kernel.org/stable/c/7b22466648a4f8e3e94f57ca428d1531866d1373
- https://git.kernel.org/stable/c/a269333fa5c0c8e53c92b5a28a6076a28cde3e83
- https://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.193
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.42
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.12.9
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.13
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.124