Back

CRITICAL

Memory leak in ICMP6 in Linux Kernel

Published Mar 18, 2022

Description

Memory leak in icmp6 implementation in Linux Kernel 5.13+ allows a remote attacker to DoS a host by making it go out-of-memory via icmp6 packets of type 130 or 131. We recommend upgrading past commit 2d3916f3189172d5c69d33065c3c21119fe539fc.

Affected products

Remediation

Red Hat statement

The impact is limited, due to ICMPv6 only possible by a remote system crash (without the possibility of exploiting a remote system).

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

References (9)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner Google
Published Mar 18, 2022
Updated Apr 21, 2025
Reserved Feb 23, 2022

CISA Vulnrichment

Updated Apr 21, 2025

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Important
Public date Mar 3, 2022
Bugzilla 2059294

ENISA EUVD

Assigner Google
Published Mar 18, 2022
Updated Apr 21, 2025

GitHub

No data