Bugzilla – Bug 1204376
VUL-1: CVE-2022-3527: iproute2: memory leak in ipneigh_get() (ip/ipneigh.c)
Last modified: 2024-07-04 09:13:21 UTC
CVE-2022-3527 A vulnerability, which was classified as problematic, has been found in Linux Kernel. This issue affects the function ipneigh_get of the file ip/ipneigh.c of the component iproute2. The manipulation leads to memory leak. The attack may be initiated remotely. It is recommended to apply a patch to fix this issue. The identifier VDB-211025 was assigned to this vulnerability. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-3527 http://www.cvedetails.com/cve/CVE-2022-3527/ https://www.cve.org/CVERecord?id=CVE-2022-3527 https://git.kernel.org/pub/scm/network/iproute2/iproute2-next.git/commit/?id=c5433c4b7a57d380f4cb351316f5ba5ebae9538e https://vuldb.com/?id.211025
tracking as affected: - SUSE:SLE-15-SP4:Update/iproute2
The CVE was retracted by the CNA, as the initial evaluation was incorrect. This is a bug in the commandline tool only.