CVE-2021-23133

Description

A race condition in Linux kernel SCTP sockets (net/sctp/socket.c) before 5.12-rc8 can lead to kernel privilege escalation from the context of a network service or an unprivileged process. If sctp_destroy_sock is called without sock_net(sk)->sctp.addr_wq_lock then an element is removed from the auto_asconf_splist list without any proper locking. This can be exploited by an attacker with network service privileges to escalate to root or from the context of an unprivileged user directly if a BPF_CGROUP_INET_SOCK_CREATE is attached which denies creation of some SCTP socket.

Risk Information

Base Score
7.0
MODERATE
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.093

Associated Vulnerability

VulnerabilityOS Platform
SUSE-SU-2021:1887-1(SUSE Linux Enterprise Server 12-SP5 ) kernel-azure-4.12.14-16.59.1.x86_64.rpmLinux
SUSE-SU-2021:1887-1(SUSE Linux Enterprise Server 12-SP5 ) kernel-azure-base-4.12.14-16.59.1.x86_64.rpmLinux
SUSE-SU-2021:1887-1(SUSE Linux Enterprise Server 12-SP5 ) kernel-azure-base-debuginfo-4.12.14-16.59.1.x86_64.rpmLinux
SUSE-SU-2021:1887-1(SUSE Linux Enterprise Server 12-SP5 ) kernel-azure-debuginfo-4.12.14-16.59.1.x86_64.rpmLinux
SUSE-SU-2021:1887-1(SUSE Linux Enterprise Server 12-SP5 ) kernel-azure-debugsource-4.12.14-16.59.1.x86_64.rpmLinux
SUSE-SU-2021:1887-1(SUSE Linux Enterprise Server 12-SP5 ) kernel-azure-devel-4.12.14-16.59.1.x86_64.rpmLinux
SUSE-SU-2021:1887-1(SUSE Linux Enterprise Server 12-SP5 ) kernel-devel-azure-4.12.14-16.59.1.noarch.rpmLinux
SUSE-SU-2021:1887-1(SUSE Linux Enterprise Server 12-SP5 ) kernel-source-azure-4.12.14-16.59.1.noarch.rpmLinux
SUSE-SU-2021:1887-1(SUSE Linux Enterprise Server 12-SP5 ) kernel-syms-azure-4.12.14-16.59.1.x86_64.rpmLinux
Kernel-uek update (ELSA-2021-9306) kernel-uek-5.4.17-2102.202.5.el8uek.x86_64.rpmLinux
Kernel-uek-debug update (ELSA-2021-9306) kernel-uek-debug-5.4.17-2102.202.5.el8uek.x86_64.rpmLinux
Kernel-uek-debug-devel update (ELSA-2021-9306) kernel-uek-debug-devel-5.4.17-2102.202.5.el8uek.x86_64.rpmLinux
Kernel-uek-devel update (ELSA-2021-9306) kernel-uek-devel-5.4.17-2102.202.5.el8uek.x86_64.rpmLinux
Kernel-uek-doc update (ELSA-2021-9306) kernel-uek-doc-5.4.17-2102.202.5.el8uek.noarch.rpmLinux
Kernel-uek update (ELSA-2021-9306) kernel-uek-5.4.17-2102.202.5.el7uek.x86_64.rpmLinux
Kernel-uek-debug update (ELSA-2021-9306) kernel-uek-debug-5.4.17-2102.202.5.el7uek.x86_64.rpmLinux
Kernel-uek-debug-devel update (ELSA-2021-9306) kernel-uek-debug-devel-5.4.17-2102.202.5.el7uek.x86_64.rpmLinux
Kernel-uek-devel update (ELSA-2021-9306) kernel-uek-devel-5.4.17-2102.202.5.el7uek.x86_64.rpmLinux
Kernel-uek-doc update (ELSA-2021-9306) kernel-uek-doc-5.4.17-2102.202.5.el7uek.noarch.rpmLinux
Kernel-uek-tools update (ELSA-2021-9306) kernel-uek-tools-5.4.17-2102.202.5.el7uek.x86_64.rpmLinux
Linux kernel (USN-4997-1) linux-image-aws_5.11.0.1011.11_amd64.debLinux
Linux kernel (USN-4997-1) linux-image-gcp_5.11.0.1011.11_amd64.debLinux
Linux kernel (USN-4997-1) linux-image-gke_5.11.0.1011.11_amd64.debLinux
Linux kernel (USN-4997-1) linux-image-azure_5.11.0.1009.9_amd64.debLinux
Linux kernel (USN-4997-1) linux-image-oracle_5.11.0.1010.10_amd64.debLinux
Linux kernel (USN-4997-1) linux-image-generic_5.11.0.22.23_amd64.debLinux
Linux kernel (USN-4997-1) linux-image-virtual_5.11.0.22.23_amd64.debLinux
Linux kernel (USN-4997-1) linux-image-lowlatency_5.11.0.22.23_amd64.debLinux
Linux kernel (USN-4997-1) linux-image-5.11.0-1011-aws_5.11.0-1011.11_amd64.debLinux
Linux kernel (USN-4997-1) linux-image-5.11.0-1011-gcp_5.11.0-1011.12_amd64.debLinux
Linux kernel (USN-4997-1) linux-image-5.11.0-1009-azure_5.11.0-1009.9_amd64.debLinux
Linux kernel (USN-4997-1) linux-image-5.11.0-22-generic_5.11.0-22.23_amd64.debLinux
Linux kernel (USN-4997-1) linux-image-5.11.0-1010-oracle_5.11.0-1010.10_amd64.debLinux
Linux kernel (USN-4997-1) linux-image-5.11.0-22-lowlatency_5.11.0-22.23_amd64.debLinux
Linux kernel (USN-4999-1) linux-image-aws_5.8.0.1038.40_amd64.debLinux
Linux kernel (USN-4999-1) linux-image-aws_5.8.0.1038.40~20.04.11_amd64.debLinux
Linux kernel (USN-4999-1) linux-image-gcp_5.8.0.1035.35_amd64.debLinux
Linux kernel (USN-4999-1) linux-image-gcp_5.8.0.1035.37~20.04.9_amd64.debLinux
Linux kernel (USN-4999-1) linux-image-gke_5.8.0.1035.35_amd64.debLinux
Linux kernel (USN-4999-1) linux-image-kvm_5.8.0.1030.32_amd64.debLinux
Linux kernel (USN-4999-1) linux-image-azure_5.8.0.1036.36_amd64.debLinux
Linux kernel (USN-4999-1) linux-image-azure_5.8.0.1036.38~20.04.8_amd64.debLinux
Linux kernel (USN-4999-1) linux-image-oracle_5.8.0.1033.32_amd64.debLinux
Linux kernel (USN-4999-1) linux-image-oracle_5.8.0.1033.34~20.04.9_amd64.debLinux
Linux kernel (USN-4999-1) linux-image-generic_5.8.0.59.64_amd64.debLinux
Linux kernel (USN-4999-1) linux-image-virtual_5.8.0.59.64_amd64.debLinux
Linux kernel (USN-4999-1) linux-image-lowlatency_5.8.0.59.64_amd64.debLinux
Linux kernel (USN-4999-1) linux-image-5.8.0-1030-kvm_5.8.0-1030.32_amd64.debLinux
Linux kernel (USN-4999-1) linux-image-5.8.0-1035-gcp_5.8.0-1035.37_amd64.debLinux
Linux kernel (USN-4999-1) linux-image-5.8.0-1035-gcp_5.8.0-1035.37~20.04.1_amd64.debLinux
Linux kernel (USN-4999-1) linux-image-5.8.0-1038-aws_5.8.0-1038.40_amd64.debLinux
Linux kernel (USN-4999-1) linux-image-5.8.0-1038-aws_5.8.0-1038.40~20.04.1_amd64.debLinux
Linux kernel (USN-4999-1) linux-image-5.8.0-1036-azure_5.8.0-1036.38_amd64.debLinux
Linux kernel (USN-4999-1) linux-image-5.8.0-1036-azure_5.8.0-1036.38~20.04.1_amd64.debLinux
Linux kernel (USN-4999-1) linux-image-5.8.0-59-generic_5.8.0-59.66_amd64.debLinux
Linux kernel (USN-4999-1) linux-image-5.8.0-59-generic_5.8.0-59.66~20.04.1_amd64.debLinux
Linux kernel (USN-4999-1) linux-image-5.8.0-1033-oracle_5.8.0-1033.34_amd64.debLinux
Linux kernel (USN-4999-1) linux-image-5.8.0-1033-oracle_5.8.0-1033.34~20.04.1_amd64.debLinux
Linux kernel (USN-4999-1) linux-image-generic-hwe-20.04_5.8.0.59.66~20.04.42_amd64.debLinux
Linux kernel (USN-4999-1) linux-image-virtual-hwe-20.04_5.8.0.59.66~20.04.42_amd64.debLinux
Linux kernel (USN-4999-1) linux-image-5.8.0-59-lowlatency_5.8.0-59.66_amd64.debLinux
Linux kernel (USN-4999-1) linux-image-5.8.0-59-lowlatency_5.8.0-59.66~20.04.1_amd64.debLinux
Linux kernel (USN-4999-1) linux-image-lowlatency-hwe-20.04_5.8.0.59.66~20.04.42_amd64.debLinux
Linux kernel (USN-5000-1) linux-image-aws_5.4.0.1051.33_amd64.debLinux
Linux kernel (USN-5000-1) linux-image-gcp_5.4.0.1046.33_amd64.debLinux
Linux kernel (USN-5000-1) linux-image-gke_5.4.0.1046.55_amd64.debLinux
Linux kernel (USN-5000-1) linux-image-oem_5.4.0.77.80_amd64.debLinux
Linux kernel (USN-5000-1) linux-image-oem_5.4.0.77.86~18.04.69_amd64.debLinux
Linux kernel (USN-5000-1) linux-image-azure_5.4.0.1051.30_amd64.debLinux
Linux kernel (USN-5000-1) linux-image-gkeop_5.4.0.1018.21_amd64.debLinux
Linux kernel (USN-5000-1) linux-image-oracle_5.4.0.1048.52~18.04.30_amd64.debLinux
Linux kernel (USN-5000-1) linux-image-generic_5.4.0.77.80_amd64.debLinux
Linux kernel (USN-5000-1) linux-image-gke-5.4_5.4.0.1046.55_amd64.debLinux
Linux kernel (USN-5000-1) linux-image-gke-5.4_5.4.0.1046.48~18.04.12_amd64.debLinux
Linux kernel (USN-5000-1) linux-image-virtual_5.4.0.77.80_amd64.debLinux
Linux kernel (USN-5000-1) linux-image-oem-osp1_5.4.0.77.80_amd64.debLinux
Linux kernel (USN-5000-1) linux-image-oem-osp1_5.4.0.77.86~18.04.69_amd64.debLinux
Linux kernel (USN-5000-1) linux-image-gkeop-5.4_5.4.0.1018.21_amd64.debLinux
Linux kernel (USN-5000-1) linux-image-gkeop-5.4_5.4.0.1018.19~18.04.19_amd64.debLinux
Linux kernel (USN-5000-1) linux-image-lowlatency_5.4.0.77.80_amd64.debLinux
Linux kernel (USN-5000-1) linux-image-aws-lts-20.04_5.4.0.1051.53_amd64.debLinux
Linux kernel (USN-5000-1) linux-image-gcp-lts-20.04_5.4.0.1046.55_amd64.debLinux
Linux kernel (USN-5000-1) linux-image-5.4.0-1046-gcp_5.4.0-1046.49_amd64.debLinux
Linux kernel (USN-5000-1) linux-image-5.4.0-1046-gcp_5.4.0-1046.49~18.04.1_amd64.debLinux
Linux kernel (USN-5000-1) linux-image-5.4.0-1046-gke_5.4.0-1046.48_amd64.debLinux
Linux kernel (USN-5000-1) linux-image-5.4.0-1046-gke_5.4.0-1046.48~18.04.1_amd64.debLinux
Linux kernel (USN-5000-1) linux-image-5.4.0-1051-aws_5.4.0-1051.53_amd64.debLinux
Linux kernel (USN-5000-1) linux-image-5.4.0-1051-aws_5.4.0-1051.53~18.04.1_amd64.debLinux
Linux kernel (USN-5000-1) linux-image-azure-lts-20.04_5.4.0.1051.49_amd64.debLinux
Linux kernel (USN-5000-1) linux-image-5.4.0-1018-gkeop_5.4.0-1018.19_amd64.debLinux
Linux kernel (USN-5000-1) linux-image-5.4.0-1018-gkeop_5.4.0-1018.19~18.04.1_amd64.debLinux
Linux kernel (USN-5000-1) linux-image-5.4.0-1051-azure_5.4.0-1051.53_amd64.debLinux
Linux kernel (USN-5000-1) linux-image-5.4.0-1051-azure_5.4.0-1051.53~18.04.1_amd64.debLinux
Linux kernel (USN-5000-1) linux-image-5.4.0-77-generic_5.4.0-77.86_amd64.debLinux
Linux kernel (USN-5000-1) linux-image-5.4.0-77-generic_5.4.0-77.86~18.04.1_i386.debLinux
Linux kernel (USN-5000-1) linux-image-5.4.0-77-generic_5.4.0-77.86~18.04.1_amd64.debLinux
Linux kernel (USN-5000-1) linux-image-oracle-lts-20.04_5.4.0.1048.48_amd64.debLinux
Linux kernel (USN-5000-1) linux-image-5.4.0-1048-oracle_5.4.0-1048.52_amd64.debLinux
Linux kernel (USN-5000-1) linux-image-5.4.0-1048-oracle_5.4.0-1048.52~18.04.1_amd64.debLinux
Linux kernel (USN-5000-1) linux-image-generic-hwe-18.04_5.4.0.77.86~18.04.69_i386.debLinux
Linux kernel (USN-5000-1) linux-image-generic-hwe-18.04_5.4.0.77.86~18.04.69_amd64.debLinux
Linux kernel (USN-5000-1) linux-image-virtual-hwe-18.04_5.4.0.77.86~18.04.69_i386.debLinux
Linux kernel (USN-5000-1) linux-image-virtual-hwe-18.04_5.4.0.77.86~18.04.69_amd64.debLinux
Linux kernel (USN-5000-1) linux-image-5.4.0-77-lowlatency_5.4.0-77.86_amd64.debLinux
Linux kernel (USN-5000-1) linux-image-5.4.0-77-lowlatency_5.4.0-77.86~18.04.1_i386.debLinux
Linux kernel (USN-5000-1) linux-image-5.4.0-77-lowlatency_5.4.0-77.86~18.04.1_amd64.debLinux
Linux kernel (USN-5000-1) linux-image-lowlatency-hwe-18.04_5.4.0.77.86~18.04.69_i386.debLinux
Linux kernel (USN-5000-1) linux-image-lowlatency-hwe-18.04_5.4.0.77.86~18.04.69_amd64.debLinux
Linux kernel for OEM systems (USN-5001-1) linux-image-oem-20.04_5.10.0.1033.34_amd64.debLinux
Linux kernel for OEM systems (USN-5001-1) linux-image-oem-20.04b_5.10.0.1033.34_amd64.debLinux
Linux kernel for OEM systems (USN-5001-1) linux-image-5.10.0-1033-oem_5.10.0-1033.34_amd64.debLinux
Linux kernel (USN-5003-1) linux-image-generic_4.15.0.147.134_i386.debLinux
Linux kernel (USN-5003-1) linux-image-generic_4.15.0.147.134_amd64.debLinux
Linux kernel (USN-5003-1) linux-image-virtual_4.15.0.147.134_i386.debLinux
Linux kernel (USN-5003-1) linux-image-virtual_4.15.0.147.134_amd64.debLinux
Linux kernel (USN-5003-1) linux-image-dell300x_4.15.0.1022.24_amd64.debLinux
Linux kernel (USN-5003-1) linux-image-lowlatency_4.15.0.147.134_i386.debLinux
Linux kernel (USN-5003-1) linux-image-lowlatency_4.15.0.147.134_amd64.debLinux
Linux kernel (USN-5003-1) linux-image-aws-lts-18.04_4.15.0.1106.109_amd64.debLinux
Linux kernel (USN-5003-1) linux-image-gcp-lts-18.04_4.15.0.1103.121_amd64.debLinux
Linux kernel (USN-5003-1) linux-image-4.15.0-1103-gcp_4.15.0-1103.116_amd64.debLinux
Linux kernel (USN-5003-1) linux-image-4.15.0-1106-aws_4.15.0-1106.113_amd64.debLinux
Linux kernel (USN-5003-1) linux-image-azure-lts-18.04_4.15.0.1118.91_amd64.debLinux
Linux kernel (USN-5003-1) linux-image-oracle-lts-18.04_4.15.0.1075.85_amd64.debLinux
Linux kernel (USN-5003-1) linux-image-4.15.0-1118-azure_4.15.0-1118.131_amd64.debLinux
Linux kernel (USN-5003-1) linux-image-4.15.0-1075-oracle_4.15.0-1075.83_amd64.debLinux
Linux kernel (USN-5003-1) linux-image-4.15.0-147-generic_4.15.0-147.151_i386.debLinux
Linux kernel (USN-5003-1) linux-image-4.15.0-147-generic_4.15.0-147.151_amd64.debLinux
Linux kernel (USN-5003-1) linux-image-4.15.0-1022-dell300x_4.15.0-1022.26_amd64.debLinux
Linux kernel (USN-5003-1) linux-image-4.15.0-147-lowlatency_4.15.0-147.151_i386.debLinux
Linux kernel (USN-5003-1) linux-image-4.15.0-147-lowlatency_4.15.0-147.151_amd64.debLinux
Linux kernel for cloud environments (USN-4997-2) linux-image-kvm_5.11.0.1009.9_amd64.debLinux
Linux kernel for cloud environments (USN-4997-2) linux-image-5.11.0-1009-kvm_5.11.0-1009.9_amd64.debLinux
Kernel-uek update (ELSA-2021-9349) kernel-uek-4.14.35-2047.505.4.el7uek.x86_64.rpmLinux
Kernel-uek-debug update (ELSA-2021-9349) kernel-uek-debug-4.14.35-2047.505.4.el7uek.x86_64.rpmLinux
Kernel-uek-debug-devel update (ELSA-2021-9349) kernel-uek-debug-devel-4.14.35-2047.505.4.el7uek.x86_64.rpmLinux
Kernel-uek-devel update (ELSA-2021-9349) kernel-uek-devel-4.14.35-2047.505.4.el7uek.x86_64.rpmLinux
Kernel-uek-doc update (ELSA-2021-9349) kernel-uek-doc-4.14.35-2047.505.4.el7uek.noarch.rpmLinux
Kernel-uek-tools update (ELSA-2021-9349) kernel-uek-tools-4.14.35-2047.505.4.el7uek.x86_64.rpmLinux
Kernel-uek update (ELSA-2021-9362) kernel-uek-5.4.17-2102.203.5.el8uek.x86_64.rpmLinux
Kernel-uek-debug update (ELSA-2021-9362) kernel-uek-debug-5.4.17-2102.203.5.el8uek.x86_64.rpmLinux
Kernel-uek-debug-devel update (ELSA-2021-9362) kernel-uek-debug-devel-5.4.17-2102.203.5.el8uek.x86_64.rpmLinux
Kernel-uek-devel update (ELSA-2021-9362) kernel-uek-devel-5.4.17-2102.203.5.el8uek.x86_64.rpmLinux
Kernel-uek-doc update (ELSA-2021-9362) kernel-uek-doc-5.4.17-2102.203.5.el8uek.noarch.rpmLinux
Kernel-uek-container update (ELSA-2021-9363) kernel-uek-container-5.4.17-2102.203.5.el8.x86_64.rpmLinux
Kernel-uek-container-debug update (ELSA-2021-9363) kernel-uek-container-debug-5.4.17-2102.203.5.el8.x86_64.rpmLinux
(RHSA-2021:4356) kernel security, bug fix, and enhancement update bpftool-4.18.0-348.el8.x86_64.rpmLinux
(RHSA-2021:4356) kernel security, bug fix, and enhancement update kernel-4.18.0-348.el8.x86_64.rpmLinux
(RHSA-2021:4356) kernel security, bug fix, and enhancement update kernel-abi-stablelists-4.18.0-348.el8.noarch.rpmLinux
(RHSA-2021:4356) kernel security, bug fix, and enhancement update kernel-core-4.18.0-348.el8.x86_64.rpmLinux
(RHSA-2021:4356) kernel security, bug fix, and enhancement update kernel-cross-headers-4.18.0-348.el8.x86_64.rpmLinux
(RHSA-2021:4356) kernel security, bug fix, and enhancement update kernel-debug-4.18.0-348.el8.x86_64.rpmLinux
(RHSA-2021:4356) kernel security, bug fix, and enhancement update kernel-debug-core-4.18.0-348.el8.x86_64.rpmLinux
(RHSA-2021:4356) kernel security, bug fix, and enhancement update kernel-debug-devel-4.18.0-348.el8.x86_64.rpmLinux
(RHSA-2021:4356) kernel security, bug fix, and enhancement update kernel-debug-modules-4.18.0-348.el8.x86_64.rpmLinux
(RHSA-2021:4356) kernel security, bug fix, and enhancement update kernel-debug-modules-extra-4.18.0-348.el8.x86_64.rpmLinux
(RHSA-2021:4356) kernel security, bug fix, and enhancement update kernel-devel-4.18.0-348.el8.x86_64.rpmLinux
(RHSA-2021:4356) kernel security, bug fix, and enhancement update kernel-doc-4.18.0-348.el8.noarch.rpmLinux
(RHSA-2021:4356) kernel security, bug fix, and enhancement update kernel-headers-4.18.0-348.el8.x86_64.rpmLinux
(RHSA-2021:4356) kernel security, bug fix, and enhancement update kernel-modules-4.18.0-348.el8.x86_64.rpmLinux
(RHSA-2021:4356) kernel security, bug fix, and enhancement update kernel-modules-extra-4.18.0-348.el8.x86_64.rpmLinux
(RHSA-2021:4356) kernel security, bug fix, and enhancement update kernel-tools-4.18.0-348.el8.x86_64.rpmLinux
(RHSA-2021:4356) kernel security, bug fix, and enhancement update kernel-tools-libs-4.18.0-348.el8.x86_64.rpmLinux
(RHSA-2021:4356) kernel security, bug fix, and enhancement update perf-4.18.0-348.el8.x86_64.rpmLinux
(RHSA-2021:4356) kernel security, bug fix, and enhancement update python3-perf-4.18.0-348.el8.x86_64.rpmLinux
Kernel-uek-container update (ELSA-2022-9999) kernel-uek-container-5.4.17-2136.313.6.el8.x86_64.rpmLinux
Kernel-uek-container-debug update (ELSA-2022-9999) kernel-uek-container-debug-5.4.17-2136.313.6.el8.x86_64.rpmLinux
kernel Security Update (ALAS-2021-1636) kernel-livepatch-4.14.232-176.381-1.0-0.amzn2.x86_64.rpmLinux
Concurrent Execution using Shared Resource with Improper Synchronization (Race Condition) Vulnerability (CVE-2021-23133)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234