Severity
7.5HIGH
EPSS
2.2%
top 15.55%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 18
Latest updateDec 3

Description

Memory leak in icmp6 implementation in Linux Kernel 5.13+ allows a remote attacker to DoS a host by making it go out-of-memory via icmp6 packets of type 130 or 131. We recommend upgrading past commit 2d3916f3189172d5c69d33065c3c21119fe539fc.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:HExploitability: 3.9 | Impact: 5.2

Affected Packages3 packages

NVDlinux/linux_kernel5.135.15.27+2
CVEListV5linux/kernelunspecified5.13
Debianlinux< 5.16.14-1+2

Patches

🔴Vulnerability Details

3
GHSA
GHSA-c2j9-m677-3m66: Memory leak in icmp6 implementation in Linux Kernel 52022-03-19
CVEList
Memory leak in ICMP6 in Linux Kernel2022-03-18
OSV
CVE-2022-0742: Memory leak in icmp6 implementation in Linux Kernel 52022-03-18

📋Vendor Advisories

8
Red Hat
vim: Heap-based Buffer Overflow prior to 9.0.07422022-12-03
Ubuntu
Linux kernel vulnerabilities2022-04-06
Ubuntu
Linux kernel (Intel IOTG) vulnerabilities2022-04-01
Ubuntu
Linux kernel (OEM) vulnerability2022-03-24
Ubuntu
Linux kernel vulnerabilities2022-03-22
CVE-2022-0742 (HIGH CVSS 7.5) | Memory leak in icmp6 implementation | cvebase.io