PT-2021-4240 · Linux+8 · Linux Kernel+8
Lin Ma
·
Published
2021-05-31
·
Updated
2023-07-02
·
CVE-2021-3573
CVSS v2.0
6.9
Medium
| Vector | AV:L/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 5.13-rc5
Description
A use-after-free in the function
hci sock bound ioctl() of the Linux kernel HCI subsystem was found. This occurs when a user calls ioct HCIUNBLOCKADDR or triggers a race condition with the call hci unregister dev() together with one of the calls hci sock blacklist add(), hci sock blacklist del(), hci get conn info(), or hci get auth info(). A privileged local user could use this flaw to crash the system or escalate their privileges on the system.Recommendations
For Linux kernel versions prior to 5.13-rc5, update to version 5.13-rc5 or later to resolve the issue. As a temporary workaround, consider restricting access to the
hci sock bound ioctl() function and limiting the use of ioct HCIUNBLOCKADDR until a patch is available. Additionally, restricting the use of hci unregister dev() and related functions may help minimize the risk of exploitation.Exploit
Fix
Race Condition
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Linux Kernel
Red Hat
Suse
Ubuntu