PT-2024-11195 · Linux+3 · Linux Kernel+3
Taehee Yoo
·
Published
2021-05-17
·
Updated
2025-12-15
·
CVE-2021-47146
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 5.12.0
Description
A vulnerability in the Linux kernel has been resolved, which could cause a kernel panic when the headroom size is too large in the
mld newpack() function. This function does not allow high-order page allocation, only order-0 allocation is allowed. If the headroom size exceeds the allowed limit, a kernel panic could occur in skb put(). The vulnerability can be triggered using specific test commands that create a network namespace and configure IPv6 addresses.Recommendations
To resolve this issue, update the Linux kernel to a version that includes the fix for the
mld newpack() function. Specifically, versions prior to 5.12.0 are affected, so updating to 5.12.0 or later should resolve the issue.At the moment, there is no information about a newer version that contains a fix for this vulnerability, other than updating to version 5.12.0 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Linux Kernel
Suse
Ubuntu