Memory leak in Linux kernel - CVE-2021-46972
Published: June 10, 2024 / Updated: May 13, 2025
Vulnerability identifier: #VU91661
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-46972
CWE-ID: CWE-401
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to memory leak within the ovl_lookup() function in fs/overlayfs/namei.c. A local user can perform a denial of service (DoS) attack.
Affected software
Linux kernel
Oracle Linux
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Real Time for NFV
Red Hat Enterprise Linux for Real Time
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
IBM Qradar SIEM
Juniper Secure Analytics (JSA)
Technical Support Appliance
Red Hat OpenShift Dev Spaces
OpenShift Logging
IBM Cloud Pak for Business Automation
IBM Business Automation Workflow
Red Hat OpenShift Container Platform
kernel (Red Hat package)
kernel-rt (Red Hat package)
kernel-debug-modules
kernel-doc
kernel-debug-modules-extra
kernel-devel
kernel-headers
kernel-modules
kernel-modules-extra
kernel-tools
kernel-tools-libs
kernel-tools-libs-devel
perf
python3-perf
kernel-abi-stablelists
kernel-debug-devel
kernel-debug-core
kernel-debug
kernel-cross-headers
kernel-core
kernel
bpftool
IBM QRadar Network Packet Capture
Oracle Linux
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Real Time for NFV
Red Hat Enterprise Linux for Real Time
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
IBM Qradar SIEM
Juniper Secure Analytics (JSA)
Technical Support Appliance
Red Hat OpenShift Dev Spaces
OpenShift Logging
IBM Cloud Pak for Business Automation
IBM Business Automation Workflow
Red Hat OpenShift Container Platform
kernel (Red Hat package)
kernel-rt (Red Hat package)
kernel-debug-modules
kernel-doc
kernel-debug-modules-extra
kernel-devel
kernel-headers
kernel-modules
kernel-modules-extra
kernel-tools
kernel-tools-libs
kernel-tools-libs-devel
perf
python3-perf
kernel-abi-stablelists
kernel-debug-devel
kernel-debug-core
kernel-debug
kernel-cross-headers
kernel-core
kernel
bpftool
IBM QRadar Network Packet Capture
How to mitigate CVE-2021-46972
Install update from vendor's website.
Linux kernel - addressed in versions 5.10.35, 5.11.19, 5.12.2, 5.13
IBM Qradar SIEM - update to 7.5.0 Update Pack 9 IF02
Juniper Secure Analytics (JSA) - update to 7.5.0 UP9 IF02
Technical Support Appliance - update to 3.0.1
Red Hat OpenShift Dev Spaces - update to 3.15.0
Red Hat OpenShift Container Platform - addressed in versions 4.13.45, 4.14.32, 4.14.33, 4.15.21
kernel (Red Hat package) - update to 4.18.0-553.8.1.el8_10
kernel-rt (Red Hat package) - update to 4.18.0-553.8.1.rt7.349.el8_10
kernel-debug-modules - update to 4.18.0-553.8.1.0.1
kernel-doc - update to 4.18.0-553.8.1.0.1
kernel-debug-modules-extra - update to 4.18.0-553.8.1.0.1
kernel-devel - update to 4.18.0-553.8.1.0.1
kernel-headers - update to 4.18.0-553.8.1.0.1
kernel-modules - update to 4.18.0-553.8.1.0.1
kernel-modules-extra - update to 4.18.0-553.8.1.0.1
kernel-tools - update to 4.18.0-553.8.1.0.1
kernel-tools-libs - update to 4.18.0-553.8.1.0.1
kernel-tools-libs-devel - update to 4.18.0-553.8.1.0.1
perf - update to 4.18.0-553.8.1.0.1
python3-perf - update to 4.18.0-553.8.1.0.1
kernel-abi-stablelists - update to 4.18.0-553.8.1.0.1
kernel-debug-devel - update to 4.18.0-553.8.1.0.1
kernel-debug-core - update to 4.18.0-553.8.1.0.1
kernel-debug - update to 4.18.0-553.8.1.0.1
kernel-cross-headers - update to 4.18.0-553.8.1.0.1
kernel-core - update to 4.18.0-553.8.1.0.1
kernel - update to 4.18.0-553.8.1.0.1
bpftool - update to 4.18.0-553.8.1.0.1
OpenShift Logging - update to 5.6.21
IBM QRadar Network Packet Capture - update to 7.5.0 Update Package 10
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF035, 24.0.0-IF001
IBM Business Automation Workflow - update to 24.0.0-IF002
IBM Qradar SIEM - update to 7.5.0 Update Pack 9 IF02
Juniper Secure Analytics (JSA) - update to 7.5.0 UP9 IF02
Technical Support Appliance - update to 3.0.1
Red Hat OpenShift Dev Spaces - update to 3.15.0
Red Hat OpenShift Container Platform - addressed in versions 4.13.45, 4.14.32, 4.14.33, 4.15.21
kernel (Red Hat package) - update to 4.18.0-553.8.1.el8_10
kernel-rt (Red Hat package) - update to 4.18.0-553.8.1.rt7.349.el8_10
kernel-debug-modules - update to 4.18.0-553.8.1.0.1
kernel-doc - update to 4.18.0-553.8.1.0.1
kernel-debug-modules-extra - update to 4.18.0-553.8.1.0.1
kernel-devel - update to 4.18.0-553.8.1.0.1
kernel-headers - update to 4.18.0-553.8.1.0.1
kernel-modules - update to 4.18.0-553.8.1.0.1
kernel-modules-extra - update to 4.18.0-553.8.1.0.1
kernel-tools - update to 4.18.0-553.8.1.0.1
kernel-tools-libs - update to 4.18.0-553.8.1.0.1
kernel-tools-libs-devel - update to 4.18.0-553.8.1.0.1
perf - update to 4.18.0-553.8.1.0.1
python3-perf - update to 4.18.0-553.8.1.0.1
kernel-abi-stablelists - update to 4.18.0-553.8.1.0.1
kernel-debug-devel - update to 4.18.0-553.8.1.0.1
kernel-debug-core - update to 4.18.0-553.8.1.0.1
kernel-debug - update to 4.18.0-553.8.1.0.1
kernel-cross-headers - update to 4.18.0-553.8.1.0.1
kernel-core - update to 4.18.0-553.8.1.0.1
kernel - update to 4.18.0-553.8.1.0.1
bpftool - update to 4.18.0-553.8.1.0.1
OpenShift Logging - update to 5.6.21
IBM QRadar Network Packet Capture - update to 7.5.0 Update Package 10
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF035, 24.0.0-IF001
IBM Business Automation Workflow - update to 24.0.0-IF002
External References
- https://git.kernel.org/stable/c/71d58457a8afc650da5d3292a7f7029317654d95
- https://git.kernel.org/stable/c/cf3e3330bc5719fa9d658e3e2f596bde89344a94
- https://git.kernel.org/stable/c/d587cfaef72b1b6f4b2774827123bce91f497cc8
- https://git.kernel.org/stable/c/eaab1d45cdb4bb0c846bd23c3d666d5b90af7b41
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.35
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.11.19
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.12.2
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.13
Related Security Bulletins
- Memory leak in Linux kernel overlayfs
- Red Hat Enterprise Linux 8 update for kernel
- Red Hat Enterprise Linux 8 update for kernel-rt
- Multiple vulnerabilities in Oracle Linux
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Dev Spaces
- Multiple vulnerabilities in OpenShift Logging 5.6
- Multiple vulnerabilities in IBM Qradar SIEM
- Multiple vulnerabilities in IBM Business Automation Workflow
- Multiple vulnerabilities in Juniper Secure Analytics (JSA)
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Multiple vulnerabilities in IBM QRadar Network Packet Capture
- Multiple vulnerabilities in IBM Technical Suppport Appliance
- Anolis OS update for kernel