Memory leak in ICMP6 in Linux Kernel
Published Mar 18, 2022
9.1
CRITICALCVSS 3.1
EPSS 5.04%
Description
Memory leak in icmp6 implementation in Linux Kernel 5.13+ allows a remote attacker to DoS a host by making it go out-of-memory via icmp6 packets of type 130 or 131. We recommend upgrading past commit 2d3916f3189172d5c69d33065c3c21119fe539fc.
Affected products
-
Affected
- ≥ unspecified, ≤ 5.13
Configuration 1
- ≥ 5.13 · < 5.15.27
- ≥ 5.16 · < 5.16.13
- 5.17
- 5.17
- 5.17
- 5.17
- 5.17
- 5.17
Configuration 2
- n/a
Configuration 3
- n/a
Configuration 4
- n/a
Configuration 5
- n/a
Configuration 6
- n/a
Configuration 7
- n/a
Configuration 8
- n/a
Configuration 9
- n/a
Configuration 10
- n/a
Configuration 11
- n/a
Configuration 12
- n/a
Configuration 13
- n/a
Configuration 14
- n/a
No data.
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The impact is limited, due to ICMPv6 only possible by a remote system crash (without the possibility of exploiting a remote system).
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
References (9)
- https://access.redhat.com/security/cve/CVE-2022-0742 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2059294 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-15809 Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=2d3916f3189172d5c69d33065c3c21119fe539fc x_refsource_MISCPatchVendor Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/net/ipv6/mcast.c?h=v5.17-rc7&id=2d3916f3189172d5c69d33065c3c21119fe539fc
- https://nvd.nist.gov/vuln/detail/CVE-2022-0742
- https://security.netapp.com/advisory/ntap-20220425-0001/ x_refsource_CONFIRMThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-0742
- https://www.openwall.com/lists/oss-security/2022/03/15/3 x_refsource_MISCMailing ListThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-0742 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2059294 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-15809 | Advisory | |
| https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=2d3916f3189172d5c69d33065c3c21119fe539fc | x_refsource_MISCPatchVendor Advisory | |
| https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/net/ipv6/mcast.c?h=v5.17-rc7&id=2d3916f3189172d5c69d33065c3c21119fe539fc | ||
| https://nvd.nist.gov/vuln/detail/CVE-2022-0742 | ||
| https://security.netapp.com/advisory/ntap-20220425-0001/ | x_refsource_CONFIRMThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2022-0742 | ||
| https://www.openwall.com/lists/oss-security/2022/03/15/3 | x_refsource_MISCMailing ListThird Party Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data