SB20250226101 - Memory leak in Linux kernel net driver
Published: February 26, 2025 Updated: May 11, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Memory leak (CVE-ID: CVE-2022-49461)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to memory leak within the amt_rcv() function in drivers/net/amt.c. A remote attacker on the local network can send specially crafted advertisement messages to the system and perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/19bb2d57eac86a368839a92117d8a10ab7183623
- https://git.kernel.org/stable/c/e7322da399fb86a2072f008b56f7160afa1b2051
- https://git.kernel.org/stable/c/fe29794c3585d039fefebaa2b5a4932a627ad4fd
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.17.14
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.18.3
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.19