PT-2024-35658 · Linux · Linux Kernel
Syzbot
·
Published
2024-11-26
·
Updated
2025-01-01
·
CVE-2024-53211
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A vulnerability has been resolved in the Linux kernel. The issue is related to the net/l2tp module, specifically in the l2tp exit net function. The problem occurs when the IDR (ID Resolver) is not properly checked for emptiness before destruction, potentially leading to a warning. This is caused by the radix tree of the IDR containing internal radix-tree nodes, which are cleaned by idr destroy. The vulnerability can be provoked by forcing memory allocation failures in idr alloc 32.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Resource Exhaustion
Improper Resource Release
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel