SB2019093029 - Denial of service in Linux kernel ipv6
Published: September 30, 2019 Updated: May 30, 2024
Security Bulletin ID
SB2019093029
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Local access
Highest impact
Denial of service
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Memory leak (CVE-ID: CVE-2019-16994)
The vulnerability allows a local user to perform DoS attack on the target system.
The vulnerability exists due memory leak within the sit_init_net() function in net/ipv6/sit.c. A local user can perform denial of service attack.
Remediation
Install update from vendor's website.
References
- https://github.com/torvalds/linux/commit/07f12b26e21ab359261bf75cfcb424fdc7daeb6d
- https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=07f12b26e21ab359261bf75cfcb424fdc7daeb6d
- https://security.netapp.com/advisory/ntap-20191031-0005/
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00021.html