PT-2021-4247 · Linux+9 · Linux Kernel+9

Or Cohen

·

Published

2021-04-13

·

Updated

2024-06-15

·

CVE-2021-23133

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.12-rc8
Description A race condition in the Linux kernel's SCTP sockets can lead to kernel privilege escalation. This issue arises when sctp destroy sock is called without proper locking, allowing an element to be removed from the auto asconf splist list. An attacker with network service privileges can exploit this to escalate to root, or an unprivileged user can exploit it directly if a BPF CGROUP INET SOCK CREATE is attached, which denies the creation of some SCTP sockets.
Recommendations For Linux kernel versions prior to 5.12-rc8, update to version 5.12-rc8 or later to resolve the issue. As a temporary workaround, consider restricting the use of SCTP sockets or disabling the sctp destroy sock function until a patch is available. Additionally, avoid using BPF CGROUP INET SOCK CREATE to deny the creation of SCTP sockets until the issue is resolved.

Exploit

Fix

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2021:4356
ALT-PU-2021-1706
ALT-PU-2021-1707
ALT-PU-2021-1720
ALT-PU-2021-1739
ALT-PU-2021-1805
ALT-PU-2021-1833
ALT-PU-2021-1855
ALT-PU-2021-1856
ALT-PU-2021-1888
ALT-PU-2021-1896
ALT-PU-2021-1912
ALT-PU-2021-1961
ALT-PU-2021-1983
ALT-PU-2021-1990
ALT-PU-2021-2370
ALT-PU-2021-2672
ALT-PU-2021-2677
ALT-PU-2021-2678
ALT-PU-2021-2737
ALT-PU-2021-2751
ALT-PU-2021-3481
ALT-PU-2022-1240
ALT-PU-2022-1419
ALT-PU-2022-1421
ALT-PU-2023-1814
AZL-6530
BDU:2021-04855
CESA-2021_4140
CESA-2021_4356
CVE-2021-23133
DLA-2689-1
DLA-2690-1
MGASA-2021-0204
MGASA-2021-0205
MGASA-2021-0214
MGASA-2021-0215
OESA-2021-1176
OPENSUSE-SU-2024:10728-1
OPENSUSE-SU-2024:13704-1
RHSA-2021:4140
RHSA-2021:4356
RHSA-2021_4140
RHSA-2021_4356
SUSE-SU-2021:1887-1
SUSE-SU-2021:1891-1
SUSE-SU-2021:1899-1
SUSE-SU-2021:1912-1
SUSE-SU-2021:1913-1
SUSE-SU-2021:2332-1
SUSE-SU-2021:2344-1
SUSE-SU-2021:2361-1
SUSE-SU-2021:2366-1
SUSE-SU-2021:2367-1
SUSE-SU-2021:2377-1
SUSE-SU-2021:2384-1
SUSE-SU-2021:2387-1
SUSE-SU-2021:2421-1
SUSE-SU-2021:2453-1
SUSE-SU-2021:2460-1
SUSE-SU-2021:2577-1
SUSE-SU-2021_2366-1
SUSE-SU-2021_2384-1
USN-4997-1
USN-4997-2
USN-4999-1
USN-5000-1
USN-5000-2
USN-5001-1
USN-5003-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Linux Kernel
Red Hat
Red Os
Suse
Ubuntu