PT-2021-4240 · Linux+8 · Linux Kernel+8

Lin Ma

·

Published

2021-05-31

·

Updated

2023-07-02

·

CVE-2021-3573

CVSS v2.0

6.9

Medium

VectorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.13-rc5
Description A use-after-free in the function hci sock bound ioctl() of the Linux kernel HCI subsystem was found. This occurs when a user calls ioct HCIUNBLOCKADDR or triggers a race condition with the call hci unregister dev() together with one of the calls hci sock blacklist add(), hci sock blacklist del(), hci get conn info(), or hci get auth info(). A privileged local user could use this flaw to crash the system or escalate their privileges on the system.
Recommendations For Linux kernel versions prior to 5.13-rc5, update to version 5.13-rc5 or later to resolve the issue. As a temporary workaround, consider restricting access to the hci sock bound ioctl() function and limiting the use of ioct HCIUNBLOCKADDR until a patch is available. Additionally, restricting the use of hci unregister dev() and related functions may help minimize the risk of exploitation.

Exploit

Fix

Race Condition

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2021:4356
ALT-PU-2021-2284
ALT-PU-2021-2486
ALT-PU-2021-2521
ALT-PU-2021-2522
ALT-PU-2021-2523
ALT-PU-2021-2590
ALT-PU-2021-2591
ALT-PU-2021-2602
ALT-PU-2021-2616
ALT-PU-2021-2658
ALT-PU-2021-2672
ALT-PU-2021-2677
ALT-PU-2021-2678
ALT-PU-2021-2691
ALT-PU-2021-2737
ALT-PU-2021-2751
ALT-PU-2021-3563
ALT-PU-2021-3573
ALT-PU-2022-1240
ALT-PU-2022-1419
ALT-PU-2022-1421
ALT-PU-2023-1814
AZL-6574
BDU:2021-04846
CESA-2021_4140
CESA-2021_4356
CESA-2022_0620
CVE-2021-3573
DLA-2689-1
DLA-2690-1
MGASA-2021-0257
MGASA-2021-0258
OESA-2021-1279
OPENSUSE-SU-2021:2305-1
OPENSUSE-SU-2021:2352-1
OPENSUSE-SU-2021_2305-1
OPENSUSE-SU-2021_2352-1
RHSA-2021:4140
RHSA-2021:4356
RHSA-2021_4140
RHSA-2021_4356
RHSA-2022:0620
RHSA-2022:0622
RHSA-2022_0620
RHSA-2022_0622
SUSE-SU-2021:2303-1
SUSE-SU-2021:2305-1
SUSE-SU-2021:2325-1
SUSE-SU-2021:2352-1
SUSE-SU-2021:2426-1
SUSE-SU-2021:3360-1
SUSE-SU-2021:3361-1
SUSE-SU-2021:3371-1
SUSE-SU-2021:3374-1
SUSE-SU-2021:3401-1
SUSE-SU-2021:3440-1
SUSE-SU-2021:3443-1
SUSE-SU-2021:3459-1
SUSE-SU-2021_3361-1
SUSE-SU-2021_3371-1
SUSE-SU-2021_3374-1
SUSE-SU-2021_3401-1
SUSE-SU-2021_3440-1
SUSE-SU-2021_3443-1
SUSE-SU-2021_3459-1
USN-5015-1
USN-5044-1
USN-5045-1
USN-5046-1
USN-5050-1
USN-5343-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Linux Kernel
Red Hat
Suse
Ubuntu