CVE-2021-23133

Advisory lineage Upstream: 0 Downstream: 34
Modified
Published: 22 Apr 2021, 18:00
Last modified:16 Sept 2024, 19:04

Vulnerability Summary

Overall Risk (default)
medium
38/100
CVSS Score
7 HIGH
v3.1 (nvd)
EPSS Score
0.09% LOW
0% probability +0.01%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

22 Apr 2021, 18:00
Published
Vulnerability first disclosed
16 Sept 2024, 19:04
Last Modified
Vulnerability information updated

Description

A race condition in Linux kernel SCTP sockets (net/sctp/socket.c) before 5.12-rc8 can lead to kernel privilege escalation from the context of a network service or an unprivileged process. If sctp_destroy_sock is called without sock_net(sk)->sctp.addr_wq_lock then an element is removed from the auto_asconf_splist list without any proper locking. This can be exploited by an attacker with network service privileges to escalate to root or from the context of an unprivileged user directly if a BPF_CGROUP_INET_SOCK_CREATE is attached which denies creation of some SCTP socket.

CVSS Metrics

  • v3.1MEDIUMScore: 6.7CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
  • v3.1HIGHScore: 7CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
  • v2.0MEDIUMScore: 6.9AV:L/AC:M/Au:N/C:C/I:C/A:C

EPSS Trends

Current EPSS score: 0.09% Percentile: 26%

Techniques & Countermeasures

  • CWE-362Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

    The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

Affected Systems

  • broadcombrocade_fabric_operating_system

    na

  • debiandebian_linux

    9.0

  • fedoraprojectfedora

    32 | 33 | 34

  • linux kernellinux kernel

    ≥ unspecified, < 5.12-rc8

  • linuxlinux_kernel

    ≥ 4.10, < 4.14.232 | ≥ 4.15, < 4.19.189 | ≥ 4.20, < 5.4.114 | ≥ 5.5, < 5.10.32 | ≥ 5.11, < 5.11.16

  • netappcloud_backup

    na

  • netapph300e

    na

  • netapph300s_firmware

    na

  • netapph410c_firmware

    na

  • netapph410s_firmware

    na

  • netapph500e

    na

  • netapph500s_firmware

    na

  • netapph700e

    na

  • netapph700s_firmware

    na

  • netappsolidfire_\&_hci_management_node

    na

  • netappsolidfire_baseboard_management_controller_firmware

    na

References (12)