#VU97485 Memory leak in Linux kernel - CVE-2024-46771


Vulnerability identifier: #VU97485

Vulnerability risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2024-46771

CWE-ID: CWE-401

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
Linux kernel
Operating systems & Components / Operating system

Vendor: Linux Foundation

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to memory leak within the bcm_notify() function in net/can/bcm.c. A local user can perform a denial of service (DoS) attack.

Mitigation
Install update from vendor's website.

Vulnerable software versions

Linux kernel: All versions


External links
https://git.kernel.org/stable/c/5c680022c4e28ba18ea500f3e29f0428271afa92
https://git.kernel.org/stable/c/33ed4ba73caae39f34ab874ba79138badc2c65dd
https://git.kernel.org/stable/c/aec92dbebdbec7567d9f56d7c9296a572b8fd849
https://git.kernel.org/stable/c/10bfacbd5e8d821011d857bee73310457c9c989a
https://git.kernel.org/stable/c/3b39dc2901aa7a679a5ca981a3de9f8d5658afe8
https://git.kernel.org/stable/c/4377b79323df62eb5d310354f19b4d130ff58d50
https://git.kernel.org/stable/c/abb0a615569ec008e8a93d9f3ab2d5b418ea94d4
https://git.kernel.org/stable/c/76fe372ccb81b0c89b6cd2fec26e2f38c958be85


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability