CVE-2021-26708
Advisory lineage Upstream: 0 Downstream: 9
Modified
Published: 05 Feb 2021, 07:41
Last modified:03 Aug 2024, 20:33
Vulnerability Summary
Overall Risk (default)
medium
28/100 CVSS Score
7 HIGH
v3.1 (nvd)
EPSS Score
0.94% LOW
1% probability -0.31%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
05 Feb 2021, 07:41
Published
Vulnerability first disclosed
03 Aug 2024, 20:33
Last Modified
Vulnerability information updated
Description
A local privilege escalation was discovered in the Linux kernel before 5.10.13. Multiple race conditions in the AF_VSOCK implementation are caused by wrong locking in net/vmw_vsock/af_vsock.c. The race conditions were implicitly introduced in the commits that added VSOCK multi-transport support.
CVSS Metrics
- v3.1•HIGH•Score: 7CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- v2.0•MEDIUM•Score: 6.9AV:L/AC:M/Au:N/C:C/I:C/A:C
EPSS Trends
Current EPSS score: 0.94%• Percentile: 77%
Techniques & Countermeasures
- CWE-667•Improper Locking
The product does not properly acquire or release a lock on a resource, leading to unexpected resource state changes and behaviors.
Affected Systems
- linux•linux_kernel
≥ 5.5, < 5.10.13
- netapp•aff_baseboard_management_controller
na
- netapp•baseboard_management_controller_500f_firmware
< 15.3
- netapp•baseboard_management_controller_a250_firmware
< 15.3
- netapp•cloud_backup
na
- netapp•fas_baseboard_management_controller
na
- netapp•hci_h410c_firmware
na
- netapp•solidfire_\&_hci_management_node
na
- netapp•solidfire_baseboard_management_controller_firmware
na
References (7)
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=c518adafa39f37858697ac9309c6cf1805581446
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.13
- https://www.openwall.com/lists/oss-security/2021/02/04/5
- http://www.openwall.com/lists/oss-security/2021/02/05/6
- https://security.netapp.com/advisory/ntap-20210312-0008/
- http://www.openwall.com/lists/oss-security/2021/04/09/2
- http://www.openwall.com/lists/oss-security/2022/01/25/14