A memory leak in the nfp_abm_u32_knode_replace() function in drivers/net/ethernet/netronome/nfp/abm/cls.c in the Linux kernel before 5.3.6 allows attackers to cause a denial of service (memory consumption), aka CID-78beef629fd9. Reference and upstream commit: https://github.com/torvalds/linux/commit/78beef629fd95be4ed853b2d37b832f766bd96ca
Created kernel tracking bugs for this issue: Affects: fedora-all [bug 1776853]
This was fixed for Fedora in 5.3.6 stable kernel updates.
Statement: This issue is rated as having Low impact because of the low memory conditions needed to trigger this issue.
Mitigation: To mitigate this issue, prevent module nfp from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically.