PT-2024-11246 · Linux+2 · Linux Kernel+2
Chengyang Fan
+1
·
Published
2021-06-16
·
Updated
2024-07-03
·
CVE-2021-47238
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A memory leak vulnerability has been resolved in the Linux kernel. The issue is related to the
ip mc add1 src function, where an unreferenced object is created, leading to a memory leak. The vulnerability occurs when the ip mc clear src function is removed from ip mc destroy dev, but still called in igmpv3 clear delrec, resulting in the inability to release in dev->mc list->sources through ip mc del1 src in sock close. This vulnerability can be exploited by an attacker to cause a denial-of-service (DoS) condition.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Linux Kernel
Suse