Linux Kernel BPF af_unix.c unix_release_sock memory leak
Published Oct 17, 2022
5.5
MEDIUMCVSS 3.1
EPSS 0.27%
Description
A vulnerability, which was classified as problematic, has been found in Linux Kernel. This issue affects the function unix_sock_destructor/unix_release_sock of the file net/unix/af_unix.c of the component BPF. The manipulation leads to memory leak. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-211043.
Affected products
- < 6.1
No data.
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-rt
Out of support scope
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (7)
- https://access.redhat.com/security/cve/CVE-2022-3543 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2161185 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-42909 Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf-next.git/commit/?id=7a62ed61367b8fd01bae1e18e30602c25060d824 PatchVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-3543
- https://vuldb.com/?id.211043 Permissions Required
- https://www.cve.org/CVERecord?id=CVE-2022-3543
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-3543 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2161185 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-42909 | Advisory | |
| https://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf-next.git/commit/?id=7a62ed61367b8fd01bae1e18e30602c25060d824 | PatchVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-3543 | ||
| https://vuldb.com/?id.211043 | Permissions Required | |
| https://www.cve.org/CVERecord?id=CVE-2022-3543 |
Change history (0)
No recorded changes yet.