Improper Resource Shutdown or Release in Linux kernel - CVE-2021-46953

 

Improper Resource Shutdown or Release in Linux kernel - CVE-2021-46953

Published: June 18, 2024


Vulnerability identifier: #VU92189
CSH Severity: Low
CVSS v4 BT: 5.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2021-46953
CWE-ID: CWE-404
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local privileged user to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources. A local privileged user can trigger resource exhaustion and perform a denial of service (DoS) attack.


Affected software

Linux kernel
Dell Data Protection Central
PowerProtect DP Series Appliance (IDPA)
Storage Resource Manager
EMC Cloud Tiering Appliance
Dell EMC Storage Monitoring and Reporting (SMR)
Dell Secure Connect Gateway

How to mitigate CVE-2021-46953

Install updates from vendor's website.

Linux kernel - addressed in versions 4.14.233, 4.19.191, 5.4.118, 5.10.36, 5.11.20, 5.12.3, 5.13
Storage Resource Manager - update to 5.0.1.0
Dell EMC Storage Monitoring and Reporting (SMR) - update to 5.0.1.0
Dell Secure Connect Gateway - update to 5.24.00.14
EMC Cloud Tiering Appliance - update to 13.2.0.2.29

External References

Related Security Bulletins