CVE-2022-3624
published 2022-10-21CVE-2022-3624: A vulnerability was found in Linux Kernel and classified as problematic. Affected by this issue is the function rlb_arp_xmit of the file…
PriorityP48low3.3CVSS 3.1
AVLACLPRLUINSUCNINAL
EPSS
0.25%
16.2th percentile
A vulnerability was found in Linux Kernel and classified as problematic. Affected by this issue is the function rlb_arp_xmit of the file drivers/net/bonding/bond_alb.c of the component IPsec. The manipulation leads to memory leak. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211928.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | — | — |
| linux | kernel | — | — |
CVSS provenance
nvdv3.13.3LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
osv3.3LOW
vendor_debian3.5LOW
vendor_redhat3.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Linux Kernel IPsec bond_alb.c rlb_arp_xmit memory leak (EUVD-2022-42984)
vuldb·2026-07-18·CVSS 3.3
CVE-2022-3624 [LOW] Linux Kernel IPsec bond_alb.c rlb_arp_xmit memory leak (EUVD-2022-42984)
A vulnerability identified as problematic has been detected in Linux Kernel. Affected by this issue is the function rlb_arp_xmit of the file drivers/net/bonding/bond_alb.c of the component IPsec. This manipulation causes memory leak.
This vulnerability is tracked as CVE-2022-3624. The attack is only possible within the local network. No exploit exists.
It is recommended to apply a patch to fix this issue.
GHSA
GHSA-9wx5-5c3v-3qmx: A vulnerability was found in Linux Kernel and classified as problematic
ghsa_unreviewed·2022-10-21
CVE-2022-3624 [LOW] CWE-401 GHSA-9wx5-5c3v-3qmx: A vulnerability was found in Linux Kernel and classified as problematic
A vulnerability was found in Linux Kernel and classified as problematic. Affected by this issue is the function rlb_arp_xmit of the file drivers/net/bonding/bond_alb.c of the component IPsec. The manipulation leads to memory leak. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211928.
OSV
CVE-2022-3624: A vulnerability was found in Linux Kernel and classified as problematic
osv·2022-10-21·CVSS 3.3
CVE-2022-3624 [LOW] CVE-2022-3624: A vulnerability was found in Linux Kernel and classified as problematic
A vulnerability was found in Linux Kernel and classified as problematic. Affected by this issue is the function rlb_arp_xmit of the file drivers/net/bonding/bond_alb.c of the component IPsec. The manipulation leads to memory leak. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211928.
Red Hat
kernel: memory leak in the function rlb_arp_xmit for IPsec
vendor_redhat·2022-08-10·CVSS 3.5
CVE-2022-3624 [LOW] CWE-401 kernel: memory leak in the function rlb_arp_xmit for IPsec
kernel: memory leak in the function rlb_arp_xmit for IPsec
A vulnerability was found in Linux Kernel and classified as problematic. Affected by this issue is the function rlb_arp_xmit of the file drivers/net/bonding/bond_alb.c of the component IPsec. The manipulation leads to memory leak. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211928.
A memory leak flaw was found in the Linux kernel IPSec functionality. This issue could allow a local user to crash the system.
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
Package: kernel-rt (Red Hat
Debian
CVE-2022-3624: linux - A vulnerability was found in Linux Kernel and classified as problematic. Affecte...
vendor_debian·2022·CVSS 3.5
CVE-2022-3624 [LOW] CVE-2022-3624: linux - A vulnerability was found in Linux Kernel and classified as problematic. Affecte...
A vulnerability was found in Linux Kernel and classified as problematic. Affected by this issue is the function rlb_arp_xmit of the file drivers/net/bonding/bond_alb.c of the component IPsec. The manipulation leads to memory leak. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211928.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://git.kernel.org/pub/scm/linux/kernel/git/klassert/ipsec-next.git/commit/?id=4f5d33f4f798b1c6d92b613f0087f639d9836971https://vuldb.com/?id.211928https://git.kernel.org/pub/scm/linux/kernel/git/klassert/ipsec-next.git/commit/?id=4f5d33f4f798b1c6d92b613f0087f639d9836971https://vuldb.com/?id.211928
2022-10-21
Published