Vulnerability identifier: #VU89940
Vulnerability risk: Low
CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2021-47472
CWE-ID:
CWE-401
Exploitation vector: Local
Exploit availability: No
Vulnerable software:
Linux kernel
Operating systems & Components /
Operating system
Vendor: Linux Foundation
Description
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to memory leak within the __mdiobus_register() function in drivers/net/phy/mdio_bus.c. A local user can perform a denial of service (DoS) attack.
Mitigation
Install update from vendor's website.
Vulnerable software versions
Linux kernel: All versions
External links
https://git.kernel.org/stable/c/fd2400dd4f1b8bd7a309b1b424d9e0d188151b01
https://git.kernel.org/stable/c/b89f4537d7fdbd0bafb6d8a66a484e0bc99871a4
https://git.kernel.org/stable/c/bc5f2f3431ced08300e4cb3aff35f1da14c26433
https://git.kernel.org/stable/c/2bc10dca9432fadb09e45127e258fc7127fd346d
https://git.kernel.org/stable/c/4ec0f9abc512cc02fb04daa89ccf6697e80ab417
https://git.kernel.org/stable/c/fdbffd95c4ce94d2197c504008eaac46b16bc5a4
https://git.kernel.org/stable/c/a9831afa2dc8a18205403907c41aa4e0950ac611
https://git.kernel.org/stable/c/8121d0d4fd108280f5cd7b7fe8c6592adaa37be9
https://git.kernel.org/stable/c/b0feaa8376f52357bf2fd020d0c471713a859728
https://git.kernel.org/stable/c/6a18d155d5b35ad50c8fac2be091212487ae58ec
https://git.kernel.org/stable/c/3a0dc2e35a5d6546b1db87fe985582dadc64fe7b
https://git.kernel.org/stable/c/c828115a14eacbf42042770fd68543f134e89efa
https://git.kernel.org/stable/c/0c4e87ba11eb331dca2315d484d08441b8c13193
https://git.kernel.org/stable/c/8ba94a7f7b9fc2a2b808ccceb99b77135deae21a
https://git.kernel.org/stable/c/ab609f25d19858513919369ff3d9a63c02cd9e2e
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.