#VU89950 Memory leak in Linux kernel


Published: 2024-05-30

Vulnerability identifier: #VU89950

Vulnerability risk: Low

CVSSv3.1: 4.8 [AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2021-47249

CWE-ID: CWE-401

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
Linux kernel
Operating systems & Components / Operating system

Vendor: Linux Foundation

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to memory leak within the rds_recvmsg() function in net/rds/recv.c. A local user can perform a denial of service (DoS) attack.

Mitigation
Install update from vendor's website.

Vulnerable software versions

Linux kernel:


External links
http://git.kernel.org/stable/c/8c3ec88b03e9e4ca117dcdc4204fd3edcd02084f
http://git.kernel.org/stable/c/423c6939758fb3b9cf5abbd1e7792068a5c4ae8c
http://git.kernel.org/stable/c/1f79bc8ae81c05eb112a53f981cb2c244ee50d02
http://git.kernel.org/stable/c/06b7cb0194bd1ede0dd27f3a946e7c0279fba44a
http://git.kernel.org/stable/c/2038cd15eacdf7512755c27686822e0052eb9042
http://git.kernel.org/stable/c/5946fbf48355f5a8caeff72580c7658da5966b86
http://git.kernel.org/stable/c/b25b60d076164edb3025e85aabd2cf50a5215b91
http://git.kernel.org/stable/c/49bfcbfd989a8f1f23e705759a6bb099de2cff9f


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability