Show plain JSON{"bugzilla": {"description": "kernel: memory leak in fib6_rule_suppress could result in DoS", "id": "2014623", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2014623"}, "csaw": false, "cvss3": {"cvss3_base_score": "0.0", "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:N", "status": "draft"}, "cwe": "CWE-401", "details": ["A memory leak flaw was reported in firewalld when IPv6_rpfilter is enabled and a suppress_prefix rule is present in the IPv6 routing rules. In such scenarios, every incoming packet will leak an allocation in ip6_dst_cache slab cache."], "mitigation": {"lang": "en:us", "value": "Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability."}, "name": "CVE-2021-3892", "package_state": [{"cpe": "cpe:/o:redhat:enterprise_linux:6", "fix_state": "Not affected", "package_name": "kernel", "product_name": "Red Hat Enterprise Linux 6"}, {"cpe": "cpe:/o:redhat:enterprise_linux:7", "fix_state": "Not affected", "package_name": "kernel", "product_name": "Red Hat Enterprise Linux 7"}, {"cpe": "cpe:/o:redhat:enterprise_linux:7", "fix_state": "Not affected", "package_name": "kernel-rt", "product_name": "Red Hat Enterprise Linux 7"}, {"cpe": "cpe:/o:redhat:enterprise_linux:8", "fix_state": "Not affected", "package_name": "kernel", "product_name": "Red Hat Enterprise Linux 8"}, {"cpe": "cpe:/o:redhat:enterprise_linux:8", "fix_state": "Not affected", "package_name": "kernel-rt", "product_name": "Red Hat Enterprise Linux 8"}, {"cpe": "cpe:/o:redhat:enterprise_linux:9", "fix_state": "Fix deferred", "package_name": "kernel", "product_name": "Red Hat Enterprise Linux 9"}], "public_date": "2019-10-03T12:08:00Z", "references": ["https://www.cve.org/CVERecord?id=CVE-2021-3892\nhttps://nvd.nist.gov/vuln/detail/CVE-2021-3892\nhttps://lore.kernel.org/lkml/20191003154533.875309419@linuxfoundation.org/"], "statement": "This flaw was found to be a duplicate of CVE-2019-18198. Please see https://access.redhat.com/security/cve/CVE-2019-18198 for information about affected products and security errata."}