SB20250226145 - Memory leak in Linux kernel bpf
Published: February 26, 2025 Updated: May 11, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Memory leak (CVE-ID: CVE-2022-49658)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to memory leak within the __reg_bound_offset(), __reg_combine_32_into_64(), __reg64_bound_u32(), __reg_combine_64_into_32(), do_refine_retval_range(), adjust_ptr_min_max_vals(), adjust_scalar_min_max_vals(), check_alu_op() and __reg_combine_min_max() functions in kernel/bpf/verifier.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/3844d153a41adea718202c10ae91dc96b37453b5
- https://git.kernel.org/stable/c/a7de8d436db92bab8b1f44624297c2554a6ac36b
- https://git.kernel.org/stable/c/b2a28bb36664c94375926cbbb91976242847699d
- https://git.kernel.org/stable/c/e917be1f83ea14a68b3cf64d3da9968eaf991dae
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.130