#VU92173 Improper Initialization in Linux kernel


Published: 2024-06-17

Vulnerability identifier: #VU92173

Vulnerability risk: Low

CVSSv3.1: 2.2 [CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C]

CVE-ID: CVE-2021-46932

CWE-ID: CWE-665

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
Linux kernel
Operating systems & Components / Operating system

Vendor: Linux Foundation

Description

The vulnerability allows a local user to perform a denial of service attack.

The vulnerability exists due to improper initialization. A local user can run a specially crafted application to perform a denial of service attack.

Mitigation
Install updates from vendor's website.

Vulnerable software versions

Linux kernel:


External links
http://git.kernel.org/stable/c/d2cb2bf39a6d17ef4bdc0e59c1a35cf5751ad8f4
http://git.kernel.org/stable/c/d1962f263a176f493400b8f91bfbf2bfedce951e
http://git.kernel.org/stable/c/292d2ac61fb0d9276a0f7b7ce4f50426f2a1c99f
http://git.kernel.org/stable/c/a02e1404e27855089d2b0a0acc4652c2ce65fe46
http://git.kernel.org/stable/c/975774ea7528b489930b76a77ffc4d5379b95ff2
http://git.kernel.org/stable/c/9f329d0d6c91142cf0ad08d23c72dd195db2633c
http://git.kernel.org/stable/c/e79ff8c68acb1eddf709d3ac84716868f2a91012
http://git.kernel.org/stable/c/9f3ccdc3f6ef10084ceb3a47df0961bec6196fd0


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability