CVE-2021-23133

Aliases:UBUNTU-CVE-2021-23133DEBIAN-CVE-2021-23133
Advisory lineage Upstream: 0 Downstream: 34
Analyzed
Published: 22 Apr 2021, 18:00
Last modified:16 Sept 2024, 19:04

Vulnerability Summary

Overall Risk (default)
medium
38/100
CVSS Score
7 HIGH
v3.1 (nvd)
EPSS Score
0.47% LOW
0% probability +0.39%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

22 Apr 2021, 18:00
Published
Vulnerability first disclosed
16 Sept 2024, 19:04
Last Modified
Vulnerability information updated

Description

A race condition in Linux kernel SCTP sockets (net/sctp/socket.c) before 5.12-rc8 can lead to kernel privilege escalation from the context of a network service or an unprivileged process. If sctp_destroy_sock is called without sock_net(sk)->sctp.addr_wq_lock then an element is removed from the auto_asconf_splist list without any proper locking. This can be exploited by an attacker with network service privileges to escalate to root or from the context of an unprivileged user directly if a BPF_CGROUP_INET_SOCK_CREATE is attached which denies creation of some SCTP socket.

CVSS Metrics

  • v3.1MEDIUMScore: 6.7CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
  • v3.1HIGHScore: 7CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
  • v2.0MEDIUMScore: 6.9AV:L/AC:M/Au:N/C:C/I:C/A:C

EPSS Trends

Current EPSS score: 0.47% Percentile: 40%

Techniques & Countermeasures

  • CWE-362Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

    The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

Affected Systems

  • broadcombrocade_fabric_operating_system

    na

  • debianlinux

    < 5.10.38-1 | < 5.10.38-1 | < 5.10.38-1 | < 5.10.38-1

  • ubuntulinux

    < 4.15.0-147.151 | < 5.4.0-77.86

  • ubuntulinux-aws

    < 4.15.0-1106.113 | < 5.4.0-1051.53

  • ubuntulinux-aws-5.0

    all

  • ubuntulinux-aws-5.3

    all

  • ubuntulinux-aws-5.4

    < 5.4.0-1051.53~18.04.1

  • ubuntulinux-aws-5.8

    < 5.8.0-1038.40~20.04.1

  • ubuntulinux-aws-fips

    < 4.15.0-2048.50 | all | < 5.4.0-1069.73+fips2

  • ubuntulinux-aws-hwe

    < 4.15.0-1106.113~16.04.1

  • ubuntulinux-azure

    < 4.15.0-1118.131~14.04.1 | < 4.15.0-1118.131~16.04.1 | all | < 5.4.0-1051.53

  • ubuntulinux-azure-4.15

    < 4.15.0-1118.131

  • ubuntulinux-azure-5.3

    all

  • ubuntulinux-azure-5.4

    < 5.4.0-1051.53~18.04.1

  • ubuntulinux-azure-5.8

    < 5.8.0-1036.38~20.04.1

  • ubuntulinux-azure-edge

    all

  • ubuntulinux-azure-fde-5.19

    all

  • ubuntulinux-azure-fips

    < 4.15.0-2030.33 | all | < 5.4.0-1073.76+fips1

  • ubuntulinux-bluefield

    all | < 5.4.0-1013.16

  • ubuntulinux-dell300x

    < 4.15.0-1022.26

  • ubuntulinux-fips

    < 4.15.0-1063.71 | all | < 5.4.0-1028.32

  • ubuntulinux-gcp

    < 4.15.0-1103.116~16.04.1 | all | < 5.4.0-1046.49

  • ubuntulinux-gcp-4.15

    < 4.15.0-1103.116

  • ubuntulinux-gcp-5.3

    all

  • ubuntulinux-gcp-5.4

    < 5.4.0-1046.49~18.04.1

  • ubuntulinux-gcp-5.8

    < 5.8.0-1035.37~20.04.1

  • ubuntulinux-gcp-edge

    all

  • ubuntulinux-gcp-fips

    all | < 5.4.0-1067.71~20.04.1

  • ubuntulinux-gke

    < 5.4.0-1046.48

  • ubuntulinux-gke-4.15

    all

  • ubuntulinux-gke-5.4

    < 5.4.0-1046.48~18.04.1

  • ubuntulinux-gkeop

    < 5.4.0-1018.19

  • ubuntulinux-gkeop-5.4

    < 5.4.0-1018.19~18.04.1

  • ubuntulinux-hwe

    < 4.15.0-147.151~16.04.1 | all

  • ubuntulinux-hwe-5.4

    < 5.4.0-77.86~18.04.1

  • ubuntulinux-hwe-5.8

    < 5.8.0-59.66~20.04.1

  • ubuntulinux-hwe-edge

    all | all

  • ubuntulinux-intel-iot-realtime

    all

  • ubuntulinux-kvm

    < 4.15.0-1094.96 | < 5.4.0-1041.42

  • ubuntulinux-oem

    all

  • ubuntulinux-oem-5.10

    < 5.10.0-1032.33

  • ubuntulinux-oem-5.6

    all

  • ubuntulinux-oracle

    < 4.15.0-1075.83~16.04.1 | < 4.15.0-1075.83 | < 5.4.0-1048.52

  • ubuntulinux-oracle-5.0

    all

  • ubuntulinux-oracle-5.3

    all

  • ubuntulinux-oracle-5.4

    < 5.4.0-1048.52~18.04.1

  • ubuntulinux-oracle-5.8

    < 5.8.0-1033.34~20.04.1

  • ubuntulinux-raspi

    < 5.4.0-1038.41

  • ubuntulinux-raspi-5.4

    < 5.4.0-1038.41~18.04.1

  • ubuntulinux-raspi-realtime

    all

Showing first 50 affected entries in server-rendered view.

References (23)