CVE-2021-23133Medium· 6.7▾ SunlitA race condition in Linux kernel SCTP sockets (net/sctp/socket.c) before 5.12-rc8 can lead to kernel privilege escalation from the context of a network service or an unprivileged process. If sctp_destroy_sock is called without sock_net(s…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 36.9 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 30.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.5%
A race condition in Linux kernel SCTP sockets (net/sctp/socket.c) before 5.12-rc8 can lead to kernel privilege escalation from the context of a network service or an unprivileged process. If sctp_destroy_sock is called without sock_net(sk)->sctp.addr_wq_lock then an element is removed from the auto_asconf_splist list without any proper locking. This can be exploited by an attacker with network service privileges to escalate to root or from the context of an unprivileged user directly if a BPF_CGROUP_INET_SOCK_CREATE is attached which denies creation of some SCTP socket.
linux_kernel < 4.4.269linux_kernel >= 4.5, < 4.9.269linux_kernel >= 4.10, < 4.14.233linux_kernel >= 4.15, < 4.19.191linux_kernel >= 4.20, < 5.4.119linux_kernel >= 5.5, < 5.10.37linux_kernel >= 5.11, < 5.11.21linux_kernel >= 5.12, < 5.12.4fedora = 32fedora = 33fedora = 34debian_linux = 9.0cloud_backupsolidfire_&_hci_management_nodebrocade_fabric_operating_systemh410c_firmwareh300s_firmwareh500s_firmwareh700s_firmwareh300e_firmwareh500e_firmwareh700e_firmwareh410s_firmwaresolidfire_baseboard_management_controller_firmwareUpgrade past the affected range:
linux_kernel 5.12.4Connected by shared product, vendor, weakness, or advisory.
CVE-2021-3483High· 7.8A flaw was found in the Nosy driver in the Linux kernel
CVE-2021-23134High· 7.8Use After Free vulnerability in nfc sockets in the Linux Kernel before 5.12.4 allows local attackers to elevate their privileges
CVE-2021-3506High· 7.1An out-of-bounds (OOB) memory access flaw was found in fs/f2fs/node.c in the f2fs module in the Linux kernel in versions before 5.12.0-rc4
CVE-2020-36180High· 8.1FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.cpdsadapter.DriverAdapterCPDS.
CVE-2020-36179High· 8.1FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.commons.dbcp.cpdsadapter.DriverAdapterCPDS.
CVE-2020-36184High· 8.1FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.PerUserPoolDataSource.