In the IPv4 implementation in the Linux kernel before 5.12.4, net/ipv4/route.c has an information leak because the hash table is very small.
References
Link | Resource |
---|---|
https://arxiv.org/pdf/2112.09604.pdf | Technical Description Third Party Advisory |
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.12.4 | Release Notes Vendor Advisory |
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/net/ipv4/route.c?id=aa6dd211e4b1dde9d5dc25d699d35f789ae7eeba | Patch Vendor Advisory |
https://www.oracle.com/security-alerts/cpujul2022.html | Patch Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2021-12-25T01:04:27
Updated: 2022-07-25T16:42:16
Reserved: 2021-12-25T00:00:00
Link: CVE-2021-45486
JSON object: View
NVD Information
Status : Analyzed
Published: 2021-12-25T02:15:06.710
Modified: 2023-02-24T14:45:06.417
Link: CVE-2021-45486
JSON object: View
Redhat Information
No data.
CWE