SB20241022282 - Resource management error in Linux kernel
Published: October 22, 2024 Updated: May 12, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Resource management error (CVE-ID: CVE-2024-49947)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to resource management error within the include/linux/virtio_net.h. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/d9dfd41e32ccc5198033ddd1ff1516822dfefa5a
- https://git.kernel.org/stable/c/4cc0648e9e3240496835dc698ace1d046d8d57ea
- https://git.kernel.org/stable/c/7711c419a915ee0dd91c125d2b967bbf2a72e9ac
- https://git.kernel.org/stable/c/49d14b54a527289d09a9480f214b8c586322310a
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.10.14
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.11.3
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.55