SB2025050295 - Memory leak in Linux kernel bridge
Published: May 2, 2025 Updated: May 10, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Memory leak (CVE-ID: CVE-2022-49812)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to memory leak within the __br_vlan_set_proto() and ntohs() functions in net/bridge/br_vlan.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/347f1793b573466424c550f2748ed837b6690fe7
- https://git.kernel.org/stable/c/9d45921ee4cb364910097e7d1b7558559c2f9fd2
- https://git.kernel.org/stable/c/f8926e2d2225eb7b7e11cd3fa266aaad9075b767
- https://git.kernel.org/stable/c/fc16a2c81a3eb1cbba8775f5bdc67856df903a7c
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.80