A race condition in Linux kernel SCTP sockets (net/sctp/socket.c) before 5.12-rc8 can lead to kernel privilege escalation from the context of a network service or an unprivileged process. If sctp_des…
中危 CVSS 6.7
摘要
A race condition in Linux kernel SCTP sockets (net/sctp/socket.c) before 5.12-rc8 can lead to kernel privilege escalation from the context of a network service or an unprivileged process. If sctp_destroy_sock is called without sock_net(sk)->sctp.addr_wq_lock then an element is removed from the auto_asconf_splist list without any proper locking. This can be exploited by an attacker with network service privileges to escalate to root or from the context of an unprivileged user directly if a BPF_C…
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判 · 自动通道
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
受影响产品
- :
- :
- :
- :
- :
- :
- :
- :
- :
- :
- :
- :
- :
- :
数据来源
- NVD DATABASE
原始链接
- http://www.openwall.com/lists/oss-security/2021/05/10/1 Mailing List
- http://www.openwall.com/lists/oss-security/2021/05/10/2 Mailing List
- http://www.openwall.com/lists/oss-security/2021/05/10/3 Mailing List
- http://www.openwall.com/lists/oss-security/2021/05/10/4 Mailing List
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=b166a20b07382b8bc1dcee2a448715c9c2c81b5b Mailing List
- https://lists.debian.org/debian-lts-announce/2021/06/msg00019.html Mitigation
- https://lists.debian.org/debian-lts-announce/2021/06/msg00020.html Mitigation
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CUX2CA63453G34C6KYVBLJXJXEARZI2X/ Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PAEQ3H6HKNO6KUCGRZVYSFSAGEUX23JL/ Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XZASHZVCOFJ4VU2I3BN5W5EPHWJQ7QWX/ Third Party Advisory
- https://security.netapp.com/advisory/ntap-20210611-0008/ Third Party Advisory
- https://www.openwall.com/lists/oss-security/2021/04/18/2 Exploit
- http://www.openwall.com/lists/oss-security/2021/05/10/1 Mailing List
- http://www.openwall.com/lists/oss-security/2021/05/10/2 Mailing List
- http://www.openwall.com/lists/oss-security/2021/05/10/3 Mailing List
- http://www.openwall.com/lists/oss-security/2021/05/10/4 Mailing List
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=b166a20b07382b8bc1dcee2a448715c9c2c81b5b Mailing List
- https://lists.debian.org/debian-lts-announce/2021/06/msg00019.html Mitigation
- https://lists.debian.org/debian-lts-announce/2021/06/msg00020.html Mitigation
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CUX2CA63453G34C6KYVBLJXJXEARZI2X/ Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PAEQ3H6HKNO6KUCGRZVYSFSAGEUX23JL/ Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XZASHZVCOFJ4VU2I3BN5W5EPHWJQ7QWX/ Third Party Advisory
- https://security.netapp.com/advisory/ntap-20210611-0008/ Third Party Advisory
- https://www.openwall.com/lists/oss-security/2021/04/18/2 Exploit
时间线
- nvd_ingest NVD