CVE-2009-2187Missing Release of Memory after Effective Lifetime in Opensolaris

CWE-3993 documents3 sources
Severity
4.9MEDIUMNVD
EPSS
0.1%
top 80.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 25
Latest updateMay 2

Description

Multiple memory leaks in the (1) IP and (2) IPv6 multicast implementation in the kernel in Sun Solaris 10, and OpenSolaris snv_67 through snv_93, allow local users to cause a denial of service (memory consumption) via vectors related to the association of (a) DL_ENABMULTI_REQ and (b) DL_DISABMULTI_REQ messages with ARP messages.

CVSS vector

AV:L/AC:L/C:N/I:N/A:CExploitability: 3.9 | Impact: 6.9

Affected Packages2 packages

NVDsun/opensolaris27 versions+26
NVDsun/solaris10.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-q4v2-h6h4-cgv4: Multiple memory leaks in the (1) IP and (2) IPv6 multicast implementation in the kernel in Sun Solaris 10, and OpenSolaris snv_67 through snv_93, allo2022-05-02
CVEList
CVE-2009-2187: Multiple memory leaks in the (1) IP and (2) IPv6 multicast implementation in the kernel in Sun Solaris 10, and OpenSolaris snv_67 through snv_93, allo2009-06-24
CVE-2009-2187 — SUN Opensolaris vulnerability | cvebase