CVE-2022-3524
ECS: Improper Resource Shutdown or Release (CVE-2022-3524)
mediumEPSS 0.8%
Affected
- Dell/ECS
3.8.1.0..*
Description
A memory leak flaw was found in the Linux kernel’s IPv6 functionality in how a user triggers the setsockopt of the IPV6_ADDRFORM and IPV6_DSTOPTS type. This flaw allows a user to crash the system if the setsockopt function is being called simultaneously with the IPV6_ADDRFORM type and other processes with the IPV6_DSTOPTS type. This issue is unlikely to happen unless a local process triggers IPV6_ADDRFORM.
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
DellECS
3.8.1.0Metrics
Show all metrics
Severity
medium
48.24
no public PoC known
4.3
Published
2022-10-16 00:00 UTC
CWE-404
Weakness classes (CWE)
CWE-404Class
Improper Resource Shutdown or Release
The product does not release or incorrectly releases a resource before it is made available for re-use.
cwe.mitre.org →
References & sources
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=3c52c6bb831f6335c176a0fc7214e26f43adbd11
- https://vuldb.com/?id.211021
- https://lists.debian.org/debian-lts-announce/2022/12/msg00031.htmlmailing-list
- https://lists.debian.org/debian-lts-announce/2022/12/msg00034.htmlmailing-list