Vulnerability identifier: #VU94267
Vulnerability risk: Low
CVSSv3.1: 4.8 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]
CVE-ID:
CWE-ID:
CWE-667
Exploitation vector: Local
Exploit availability: No
Vulnerable software:
Linux kernel
Operating systems & Components /
Operating system
Vendor: Linux Foundation
Description
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper locking within the tcf_idr_check_alloc() and rcu_read_unlock() functions in net/sched/act_api.c. A local user can perform a denial of service (DoS) attack.
Mitigation
Install update from vendor's website.
Vulnerable software versions
Linux kernel:
External links
http://git.kernel.org/stable/c/0d8a2d287c8a394c0d4653f0c6c7be4c688e5a74
http://git.kernel.org/stable/c/c6a7da65a296745535a964be1019ec7691b0cb90
http://git.kernel.org/stable/c/25987a97eec4d5f897cd04ee1b45170829c610da
http://git.kernel.org/stable/c/6fc78d67f51aeb9a542d39a8714e16bc411582d4
http://git.kernel.org/stable/c/5f926aa96b08b6c47178fe1171e7ae331c695fc2
http://git.kernel.org/stable/c/7a0e497b597df7c4cf2b63fc6e9188b6cabe5335
http://git.kernel.org/stable/c/d864319871b05fadd153e0aede4811ca7008f5d6
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.