PT-2024-8909 · Linux+3 · Linux Kernel+3
Syzbot
·
Published
2024-05-24
·
Updated
2025-01-06
·
CVE-2021-47512
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
Linux kernel versions prior to 5.16.0-rc4-syzkaller
Description:
The vulnerability is related to the fq pie component in the Linux kernel, which is responsible for managing network traffic. The issue arises from the fact that the fq pie destroy() function did not properly copy working code from pie destroy() and other qdiscs, leading to an elusive bug. This bug can cause a denial-of-service (DoS) condition, allowing an attacker to disrupt network services. The vulnerability is triggered when the del timer sync() function is called without ensuring that the timer will not rearm itself.
Recommendations:
To resolve this issue, update the Linux kernel to a version that includes the fix for the fq pie vulnerability. Specifically, versions 5.16.0-rc4-syzkaller and later should be used. As a temporary workaround, consider disabling the fq pie component until a patch is available. However, this may impact network performance and should be carefully evaluated before implementation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Linux Kernel
Red Os
Suse