PT-2021-8217 · Linux+3 · Linux Kernel+3
Syzbot
·
Published
2021-12-16
·
Updated
2024-12-02
·
CVE-2021-47588
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 5.16.0-rc5-syzkaller
Description
The vulnerability is related to a memory corruption issue in the sit init net() function. The ipip6 dev free() function is called from sit init net(), but it is already called by register netdevice() if something goes wrong. This can lead to a dst release underflow. The vulnerability was reported by syzbot and is related to the dst release function in the net/core/dst.c file.
Recommendations
To resolve the issue, update the Linux kernel to a version that includes the fix for this vulnerability. As a temporary workaround, consider disabling the ipip6 dev free() function until a patch is available. However, this may have unintended consequences and should be done with caution.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Linux Kernel
Red Os
Suse