SB20240530148 - Memory leak in Linux kernel fuse
Published: May 30, 2024 Updated: May 14, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Memory leak (CVE-ID: CVE-2021-46956)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to memory leak within the virtio_fs_probe() function in fs/fuse/virtio_fs.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/310efc95c72c13faf855c692d19cd4d054d827c8
- https://git.kernel.org/stable/c/d19555ff225d0896a33246a49279e6d578095f15
- https://git.kernel.org/stable/c/9b9d60c0eb8ada99cce2a9ab5c15dffc523b01ae
- https://git.kernel.org/stable/c/5116e79fc6e6725b8acdad8b7e928a83ab7b47e6
- https://git.kernel.org/stable/c/c79c5e0178922a9e092ec8fed026750f39dcaef4
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.36
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.11.20
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.12.3
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.13
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.118