A memory leak flaw was found in the Linux kernel's ccp_run_aes_gcm_cmd() function that allows an attacker to cause a denial of service. The vulnerability is similar to the older CVE-2019-18808. The highest threat from this vulnerability is to system availability.
References
Link | Resource |
---|---|
https://github.com/torvalds/linux/commit/505d9dcb0f7ddf9d075e729523a33d38642ae680 | Patch Third Party Advisory |
https://access.redhat.com/security/cve/CVE-2021-3764 | Third Party Advisory |
https://security-tracker.debian.org/tracker/CVE-2021-3764 | Third Party Advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=1997467 | Issue Tracking Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2022-08-23 09:15
Updated : 2022-08-24 19:33
NVD link : CVE-2021-3764
Mitre link : CVE-2021-3764
JSON object : View
CWE
CWE-401
Missing Release of Memory after Effective Lifetime
Products Affected
linux
- linux_kernel