In the Linux kernel, the following vulnerability has been resolved: net: rfkill: prevent unlimited numbers of rfkill events from being created Userspace can create an unlimited number of rfkill events if the system is so configured, while not consuming them from the rfkill file descriptor, causing a potential out of memory situation. Prevent this from bounding the number of pending rfkill events at a "large" number (i.e. 1000) to prevent abuses like this.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
| Attack Vector | LOCAL |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | LOW |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | NONE |
| Integrity Impact | NONE |
| Availability Impact | HIGH |
| Source | Type | Description |
|---|---|---|
| [email protected] | Primary |
en
NVD-CWE-noinfo
|
| Vendor | Product | Version | Update | Type |
|---|---|---|---|---|
| linux | linux_kernel | * | <built-in method update of dict object at 0x7d23bea8b840> | Operating System |
| linux | linux_kernel | * | <built-in method update of dict object at 0x7d242455da40> | Operating System |
| linux | linux_kernel | * | <built-in method update of dict object at 0x7d2424536a80> | Operating System |
| linux | linux_kernel | * | <built-in method update of dict object at 0x7d23beb17c00> | Operating System |
| linux | linux_kernel | * | <built-in method update of dict object at 0x7d23bea8b900> | Operating System |
| linux | linux_kernel | * | <built-in method update of dict object at 0x7d2424536240> | Operating System |
| linux | linux_kernel | * | <built-in method update of dict object at 0x7d23beb17280> | Operating System |
| linux | linux_kernel | 2.6.31 | <built-in method update of dict object at 0x7d23beb14680> | Operating System |
| linux | linux_kernel | 7.0 | <built-in method update of dict object at 0x7d23beb15e80> | Operating System |
| linux | linux_kernel | 7.0 | <built-in method update of dict object at 0x7d24245349c0> | Operating System |
| linux | linux_kernel | 7.0 | <built-in method update of dict object at 0x7d23bea8bb80> | Operating System |
| linux | linux_kernel | 7.0 | <built-in method update of dict object at 0x7d23beb16bc0> | Operating System |
| linux | linux_kernel | 7.0 | <built-in method update of dict object at 0x7d24245378c0> | Operating System |
| linux | linux_kernel | 7.0 | <built-in method update of dict object at 0x7d2424535d80> | Operating System |
| linux | linux_kernel | 7.0 | <built-in method update of dict object at 0x7d242455d600> | Operating System |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:2.6.31:-:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:7.0:rc4:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:7.0:rc5:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:7.0:rc6:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:7.0:rc7:*:*:*:*:*:* |