PT-2021-4933 · Linux+9 · Linux Kernel+9

Published

2021-10-26

·

Updated

2026-02-28

·

CVE-2021-43267

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions 5.10 through 5.15
Description The issue is related to the Transparent Inter-Process Communication (TIPC) functionality in the Linux kernel, which allows remote attackers to exploit insufficient validation of user-supplied sizes for the MSG CRYPTO message type. This can lead to a heap overflow, allowing an attacker to gain kernel privileges. The vulnerability can be exploited either locally or remotely within a network. The TIPC module needs to be loaded manually for the bug to be triggerable. There is no evidence of this vulnerability being exploited in the wild.
Recommendations For Linux kernel versions 5.10 through 5.15, update to a version that includes the security fix for this issue. As a temporary workaround, consider disabling the TIPC module to minimize the risk of exploitation. Restrict access to the TIPC functionality to prevent unauthorized use. Avoid using the MSG CRYPTO message type in the TIPC protocol until the issue is resolved.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2021:4647
ALSA-2021_4647
ALSA-2024_2394
ALSA-2025_16880
ALT-PU-2021-3220
ALT-PU-2021-3230
ALT-PU-2021-3232
ALT-PU-2021-3233
ALT-PU-2021-3268
ALT-PU-2021-3270
ALT-PU-2021-3282
ALT-PU-2021-3309
ALT-PU-2021-3375
ALT-PU-2021-3376
ALT-PU-2021-3380
ALT-PU-2021-3415
ALT-PU-2021-3444
ALT-PU-2021-3451
ALT-PU-2021-3458
ALT-PU-2021-3468
ALT-PU-2021-3469
ALT-PU-2021-3477
ALT-PU-2021-3485
ALT-PU-2021-3563
ALT-PU-2021-3573
ALT-PU-2023-4894
AZL-6603
BDU:2021-05673
CESA-2021_4645
CESA-2021_4646
CESA-2021_4647
CVE-2021-43267
ELSA-2021-4647
MGASA-2021-0507
MGASA-2021-0508
RHSA-2021:4644
RHSA-2021:4645
RHSA-2021:4646
RHSA-2021:4647
RHSA-2021:4648
RHSA-2021:4650
RHSA-2021:4750
RHSA-2021_4646
RHSA-2021_4647
RLSA-2021:4646
RLSA-2021:4647
RLSA-2021_4646
RLSA-2021_4647
USN-5165-1
USN-5207-1
USN-5208-1
USN-5218-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Linux Kernel
Red Hat
Red Os
Rocky Linux
Ubuntu