Remote DoS vulnerability in the Linux kernel exploited by sending ICMPv6 packets

A vulnerability has been identified in the Linux kernel (CVE-2022-0742) that can exhaust available memory and remotely cause a denial of service by sending specially crafted icmp6 packets. The problem is related to a memory leak that occurs when processing ICMPv6 messages with types 130 or 131.

The problem has been present since kernel 5.13 and is fixed in releases 5.16.13 and 5.15.27. The issue did not affect Debian, SUSE, Ubuntu LTS (18.04, 20.04) and RHEL stable branches, was fixed in Arch Linux, but remains unfixed in Ubuntu 21.10 and Fedora Linux.

Source: opennet.ru

Add a comment