PT-2021-8217 · Linux+3 · Linux Kernel+3

Syzbot

·

Published

2021-12-16

·

Updated

2024-12-02

·

CVE-2021-47588

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.16.0-rc5-syzkaller
Description The vulnerability is related to a memory corruption issue in the sit init net() function. The ipip6 dev free() function is called from sit init net(), but it is already called by register netdevice() if something goes wrong. This can lead to a dst release underflow. The vulnerability was reported by syzbot and is related to the dst release function in the net/core/dst.c file.
Recommendations To resolve the issue, update the Linux kernel to a version that includes the fix for this vulnerability. As a temporary workaround, consider disabling the ipip6 dev free() function until a patch is available. However, this may have unintended consequences and should be done with caution.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-11530
CVE-2021-47588
OPENSUSE-SU-2024_2947-1
SUSE-SU-2024:2892-1
SUSE-SU-2024:2894-1
SUSE-SU-2024:2901-1
SUSE-SU-2024:2939-1
SUSE-SU-2024:2940-1
SUSE-SU-2024:2947-1

Affected Products

Astra Linux
Linux Kernel
Red Os
Suse