A vulnerability has been identified in the Linux kernel (CVE-2022-0742) that allows for the exhaustion of available memory and remotely triggers a denial of service by sending specially crafted icmp6 packets. The issue is related to a memory leak that occurs when processing ICMPv6 messages with types 130 or 131.
The issue manifests starting from kernel 5.13 and has been fixed in releases 5.16.13 and 5.15.27. The problem did not affect stable branches of Debian, SUSE, Ubuntu LTS (18.04, 20.04), and RHEL, has been resolved in Arch Linux, but remains unpatched in Ubuntu 21.10 and Fedora Linux.
Source: opennet.ru
