vendor:
Linux Kernel
by:
David J. Schwartz
7.5
CVSS
HIGH
Memory Leak and TCP Port Lockup
119
CWE
Product Name: Linux Kernel
Affected Version From: Linux kernel 2.0.35
Affected Version To: Linux kernel 2.2.0pre
Patch Exists: YES
Related CWE: N/A
CPE: o:linux:linux_kernel
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
1998
Linux Kernel Memory Leak and TCP Port Lockup
It is possible to leak kernel memory and render TCP ports above 1024 unusable, locked forever in the CLOSE_WAIT state in linux kernels prior to the late 2.1.x and 2.2.0pre releases. In addition to being intentionally exploited, unix applications compiled on linux that are multithreaded may also cause these problems.
Mitigation:
Upgrade to the latest version of Linux kernel