SB2024062189 - Resource management error in Linux kernel net ipvlan driver
Published: June 21, 2024 Updated: May 13, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Resource management error (CVE-ID: CVE-2024-33621)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to resource management error within the ipvlan_process_v4_outbound() and ipvlan_process_v6_outbound() functions in drivers/net/ipvlan/ipvlan_core.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0049a623dfbbb49888de7f0c2f33a582b5ead989
- https://git.kernel.org/stable/c/54768bacfde60e8e4757968d79f8726711dd2cf5
- https://git.kernel.org/stable/c/1abbf079da59ef559d0ab4219d2a0302f7970761
- https://git.kernel.org/stable/c/183c4b416454b9983dc1b8aa0022b748911adc48
- https://git.kernel.org/stable/c/cb53706a3403ba67f4040b2a82d9cf79e11b1a48
- https://git.kernel.org/stable/c/54213c09801e0bd2549ac42961093be36f65a7d0
- https://git.kernel.org/stable/c/13c4543db34e0da5a7d2f550b6262d860f248381
- https://git.kernel.org/stable/c/b3dc6e8003b500861fa307e9a3400c52e78e4d3a
- https://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.316
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.219
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.161
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.278
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.93
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.10
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.33