Back

MEDIUM

kernel: netdevsim: fib: reference count leak on route deletion failure

Published Apr 24, 2023

Description

A flaw was found in the Linux kernel's netdevsim device driver, within the scheduling of events. This issue results from the improper management of a reference count. This may allow an attacker to create a denial of service condition on the system.

Affected products

Remediation

Red Hat statement

Red Hat Enterprise Linux 6 and 7 are not affected by this flaw as they did not ship the `netdevsim` device driver. Red Hat Enterprise Linux 8 is not affected as it did not include the upstream commit that introduced this flaw (0ae3eb7 "netdevsim: fib: Perform the route programming in a non-atomic context").

Weaknesses (1)

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Apr 24, 2023
Updated Mar 18, 2025
Reserved Apr 13, 2023
CISA Vulnrichment
Updated Mar 6, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Apr 13, 2023