Описание
A flaw was found in svxlink's remotetrx NetUplink component. When a server initiates a disconnect, the associated connection object is not properly freed, causing a memory leak. A remote attacker can repeatedly trigger disconnects to cause unbounded memory growth, leading to a denial of service.
Отчет
svxlink is not shipped in any Red Hat Enterprise product. It is available in Fedora as a community-maintained package.
Меры по смягчению последствий
Update svxlink to version 26.05.1 or later.
Дополнительная информация
Статус:
Important
Дефект:
CWE-401
https://bugzilla.redhat.com/show_bug.cgi?id=2513797svxlink: svxlink: Unbounded resource exhaustion via connection object leak in NetUplink
Связанные уязвимости
ubuntu
16 дней назад
[GHSA-5xr9-fmm8-7p8x: remotetrx NetUplink: connection object leak DoS]