PT-2021-1518 · Linux+5 · Linux Kernel+5

Ilja Van Sprundel

+1

·

Published

2021-06-28

·

Updated

2023-08-14

·

CVE-2021-3655

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to v5.14-rc1
Description The issue is related to insufficient input validation when handling SCTP packets, which may allow a remote attacker to gain unauthorized access to protected information. This could lead to remote information disclosure to an on-path attacker with no additional execution privileges needed. The vulnerability is due to a missing bounds check in functions such as sctp v6 to sk daddr and sctp v4 from addr param, potentially causing an out of bounds read. User interaction is not required for exploitation.
Recommendations For Linux kernel versions prior to v5.14-rc1, update to version v5.14-rc1 or later to resolve the issue. As a temporary workaround, consider restricting access to SCTP packets to minimize the risk of exploitation.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-2824
ALT-PU-2021-2926
ALT-PU-2021-3041
ALT-PU-2021-3563
ALT-PU-2021-3573
ALT-PU-2022-1240
ALT-PU-2022-1419
ALT-PU-2022-1421
ALT-PU-2023-1814
ALT-PU-2023-4894
ASB-A-197154735
AZL-6576
BDU:2021-03942
CVE-2021-3655
DLA-2785-1
DLA-2843-1
MGASA-2021-0366
MGASA-2021-0367
OESA-2021-1310
OPENSUSE-SU-2021:1477-1
OPENSUSE-SU-2021:3641-1
OPENSUSE-SU-2021:3675-1
OPENSUSE-SU-2021:3876-1
OPENSUSE-SU-2021_1460-1
OPENSUSE-SU-2021_1477-1
OPENSUSE-SU-2021_3641-1
OPENSUSE-SU-2021_3655-1
OPENSUSE-SU-2021_3675-1
OPENSUSE-SU-2021_3876-1
SUSE-SU-2021:14849-1
SUSE-SU-2021:3640-1
SUSE-SU-2021:3641-1
SUSE-SU-2021:3642-1
SUSE-SU-2021:3658-1
SUSE-SU-2021:3675-1
SUSE-SU-2021:3723-1
SUSE-SU-2021:3748-1
SUSE-SU-2021:3754-1
SUSE-SU-2021:3876-1
SUSE-SU-2021:3929-1
SUSE-SU-2021:3935-1
SUSE-SU-2021:3969-1
SUSE-SU-2021:3972-1
SUSE-SU-2021_14849-1
USN-5136-1
USN-5139-1
USN-5161-1
USN-5162-1
USN-5163-1

Affected Products

Alt Linux
Astra Linux
Linuxmint
Linux Kernel
Suse
Ubuntu