#VU91661 Memory leak in Linux kernel


Published: 2024-06-10

Vulnerability identifier: #VU91661

Vulnerability risk: Low

CVSSv3.1: 4.8 [AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2021-46972

CWE-ID: CWE-401

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
Linux kernel
Operating systems & Components / Operating system

Vendor: Linux Foundation

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to memory leak within the ovl_lookup() function in fs/overlayfs/namei.c. A local user can perform a denial of service (DoS) attack.

Mitigation
Install update from vendor's website.

Vulnerable software versions

Linux kernel:


External links
http://git.kernel.org/stable/c/71d58457a8afc650da5d3292a7f7029317654d95
http://git.kernel.org/stable/c/cf3e3330bc5719fa9d658e3e2f596bde89344a94
http://git.kernel.org/stable/c/d587cfaef72b1b6f4b2774827123bce91f497cc8
http://git.kernel.org/stable/c/eaab1d45cdb4bb0c846bd23c3d666d5b90af7b41


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability