PT-2024-11294 · Linux+2 · Linux Kernel+2

Cong Wang

+1

·

Published

2021-07-19

·

Updated

2024-07-18

·

CVE-2021-47293

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue arises from the tcf skbmod act() function assuming that packets use Ethernet as their L2 protocol, which is not always the case. This can lead to silent corruption of packets when using non-Ethernet protocols, such as CAN devices. The problem occurs when the skbmod action is performed on non-Ethernet packets. To demonstrate this, an example is given using CAN devices, where the ip link add and tc qdisc add commands are used to set up a network interface and traffic control, respectively. The matchall action skbmod swap mac command is then used to swap the MAC addresses of packets, which silently corrupts them.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-14595
CVE-2021-47293
RHSA-2024:4447
SUSE-SU-2024:2360-1
SUSE-SU-2024:2381-1
SUSE-SU-2024:2561-1

Affected Products

Astra Linux
Linux Kernel
Suse