CVE-2021-26708Improper Locking in Kernel

Severity
7.0HIGHNVD
EPSS
0.9%
top 23.81%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 5
Latest updateSep 7

Description

A local privilege escalation was discovered in the Linux kernel before 5.10.13. Multiple race conditions in the AF_VSOCK implementation are caused by wrong locking in net/vmw_vsock/af_vsock.c. The race conditions were implicitly introduced in the commits that added VSOCK multi-transport support.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.0 | Impact: 5.9

Affected Packages22 packages

Patches

🔴Vulnerability Details

3
Kernel
ipc, msg: Use dedicated slab buckets for alloc_msg()2024-07-01
GHSA
GHSA-hhxw-8c9w-q5q9: A local privilege escalation was discovered in the Linux kernel before 52022-05-24
OSV
CVE-2021-26708: A local privilege escalation was discovered in the Linux kernel before 52021-02-05

📋Vendor Advisories

5
Palo Alto
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS2024-02-14
Ubuntu
Linux kernel vulnerability2021-02-10
Microsoft
A local privilege escalation was discovered in the Linux kernel before 5.10.13. Multiple race conditions in the AF_VSOCK implementation are caused by wrong locking in net/vmw_vsock/af_vsock.c. The rac2021-02-09
Red Hat
kernel: race conditions caused by wrong locking in net/vmw_vsock/af_vsock.c2021-02-05
Debian
CVE-2021-26708: linux - A local privilege escalation was discovered in the Linux kernel before 5.10.13. ...2021

📄Research Papers

2
arXiv
Beyond Control: Exploring Novel File System Objects for Data-Only Attacks on Linux Systems2024-09-07
arXiv
Timeloops: Automatic System Call Policy Learning for Containerized Microservices2022-09-26