← Back

CVE-2021-23133

nvd nist
Published: Apr 22, 2021Modified: Jun 17, 2026

JSON object

Loading...
7.0
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.0 / Impact: 5.9
Source: NVD

Description

A race condition in Linux kernel SCTP sockets (net/sctp/socket.c) before 5.12-rc8 can lead to kernel privilege escalation from the context of a network service or an unprivileged process. If sctp_destroy_sock is called without sock_net(sk)->sctp.addr_wq_lock then an element is removed from the auto_asconf_splist list without any proper locking. This can be exploited by an attacker with network service privileges to escalate to root or from the context of an unprivileged user directly if a BPF_CGROUP_INET_SOCK_CREATE is attached which denies creation of some SCTP socket.

Affected (21)

Show all products
1 product
Linux Kernel
1 product
Fedora
1 product
Debian Linux
11 products
Cloud Backup
Solidfire & Hci Management Node
H410c Firmware
H300s Firmware
H500s Firmware
H700s Firmware
H300e Firmware
H500e Firmware
H700e Firmware
H410s Firmware
1 product
Brocade Fabric Operating System
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Linux
From 4.10 to 4.14.232
From 4.15 to 4.19.189
From 4.20 to 5.4.114
From 5.11 to 5.11.16
From 5.5 to 5.10.32
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 32
Version 33
Version 34
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 9.0
Configuration D
2 vulnerable
Vulnerable SoftwareAffected Versions
All versions
All versions
Configuration E
1 vulnerable
Vulnerable SoftwareAffected Versions
All versions
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
H410c
All versions
Configuration G
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
H300s
All versions
Configuration H
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
H500s
All versions
Configuration I
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
H700s
All versions
Configuration J
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
H300e
All versions
Configuration K
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
H500e
All versions
Configuration L
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
H700e
All versions
Configuration M
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
H410s
All versions
Configuration N
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
Solidfire Baseboard Management Controller
All versions

References (24)

Source: psirt@paloaltonetworks.com
Mailing ListPatchThird Party Advisory
Source: psirt@paloaltonetworks.com
Mailing ListPatchThird Party Advisory
Source: psirt@paloaltonetworks.com
Mailing ListPatchThird Party Advisory
Source: psirt@paloaltonetworks.com
Mailing ListPatchThird Party Advisory
Source: psirt@paloaltonetworks.com
MitigationThird Party Advisory
Source: psirt@paloaltonetworks.com
MitigationThird Party Advisory
Source: psirt@paloaltonetworks.com
Third Party Advisory
Source: psirt@paloaltonetworks.com
ExploitMailing ListPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMailing ListPatchThird Party Advisory

Timeline

No history available yet.