Vulnerability identifier: #VU93466
Vulnerability risk: Low
CVSSv3.1: 4.8 [AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]
CVE-ID:
CWE-ID:
CWE-399
Exploitation vector: Local
Exploit availability: No
Vulnerable software:
Linux kernel
Operating systems & Components /
Operating system
Vendor: Linux Foundation
Description
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to resource management error within the pl_vendor_req() function in drivers/net/usb/plusb.c. A local user can perform a denial of service (DoS) attack.
Mitigation
Install update from vendor's website.
Vulnerable software versions
Linux kernel:
External links
http://git.kernel.org/stable/c/f0ad46ef772438c0596df370450d8bdc8a12dbfb
http://git.kernel.org/stable/c/6f69307f625904feed189008381fd83bd1a35b63
http://git.kernel.org/stable/c/43379fcacea2dcee35d02efc9c8fe97807a503c9
http://git.kernel.org/stable/c/1be271c52bf3554edcb8d124d1f8c7f777ee5727
http://git.kernel.org/stable/c/25141fb4119112f4ebf8f00cf52014abbc8020b1
http://git.kernel.org/stable/c/0d2cf3fae701646061e295815bb7588d2f3671cc
http://git.kernel.org/stable/c/811d581194f7412eda97acc03d17fc77824b561f
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.