CVE-2022-3524

ECS: Improper Resource Shutdown or Release (CVE-2022-3524)

mediumEPSS 0.8%

Affected

  • Dell/ECS 3.8.1.0..*

Description

A memory leak flaw was found in the Linux kernel’s IPv6 functionality in how a user triggers the setsockopt of the IPV6_ADDRFORM and IPV6_DSTOPTS type. This flaw allows a user to crash the system if the setsockopt function is being called simultaneously with the IPV6_ADDRFORM type and other processes with the IPV6_DSTOPTS type. This issue is unlikely to happen unless a local process triggers IPV6_ADDRFORM.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

DellECS
3.8.1.0

Metrics

4.3
Source: cna-v3
56.0 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
Show all metrics
Severity
medium
no public PoC known
0.8 %
Low — model estimates < 1% exploitation likelihood.
Published
2022-10-16 00:00 UTC
CWE-404

Weakness classes (CWE)

  • CWE-404Class

    Improper Resource Shutdown or Release

    The product does not release or incorrectly releases a resource before it is made available for re-use.

    cwe.mitre.org →

References & sources