PT-2021-4933 · Linux+9 · Linux Kernel+9
Published
2021-10-26
·
Updated
2026-02-28
·
CVE-2021-43267
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions 5.10 through 5.15
Description
The issue is related to the Transparent Inter-Process Communication (TIPC) functionality in the Linux kernel, which allows remote attackers to exploit insufficient validation of user-supplied sizes for the MSG CRYPTO message type. This can lead to a heap overflow, allowing an attacker to gain kernel privileges. The vulnerability can be exploited either locally or remotely within a network. The TIPC module needs to be loaded manually for the bug to be triggerable. There is no evidence of this vulnerability being exploited in the wild.
Recommendations
For Linux kernel versions 5.10 through 5.15, update to a version that includes the security fix for this issue.
As a temporary workaround, consider disabling the TIPC module to minimize the risk of exploitation.
Restrict access to the TIPC functionality to prevent unauthorized use.
Avoid using the MSG CRYPTO message type in the TIPC protocol until the issue is resolved.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Linux Kernel
Red Hat
Red Os
Rocky Linux
Ubuntu