PT-2024-11195 · Linux+3 · Linux Kernel+3

Taehee Yoo

·

Published

2021-05-17

·

Updated

2025-12-15

·

CVE-2021-47146

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.12.0
Description A vulnerability in the Linux kernel has been resolved, which could cause a kernel panic when the headroom size is too large in the mld newpack() function. This function does not allow high-order page allocation, only order-0 allocation is allowed. If the headroom size exceeds the allowed limit, a kernel panic could occur in skb put(). The vulnerability can be triggered using specific test commands that create a network namespace and configure IPv6 addresses.
Recommendations To resolve this issue, update the Linux kernel to a version that includes the fix for the mld newpack() function. Specifically, versions prior to 5.12.0 are affected, so updating to 5.12.0 or later should resolve the issue.
At the moment, there is no information about a newer version that contains a fix for this vulnerability, other than updating to version 5.12.0 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-07357
CVE-2021-47146
OESA-2024-1483
OESA-2024-1484
SUSE-SU-2024:1643-1
SUSE-SU-2024:1646-1
SUSE-SU-2024:1870-1
USN-7930-1
USN-7930-2

Affected Products

Astra Linux
Linux Kernel
Suse
Ubuntu