CVE-2021-32606
published 2021-05-11CVE-2021-32606: In the Linux kernel 5.11 through 5.12.2, isotp_setsockopt in net/can/isotp.c allows privilege escalation to root by leveraging a use-after-free. (This does not…
PriorityP342high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.43%
35.7th percentile
In the Linux kernel 5.11 through 5.12.2, isotp_setsockopt in net/can/isotp.c allows privilege escalation to root by leveraging a use-after-free. (This does not affect earlier versions that lack CAN ISOTP SF_BROADCAST support.)
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| linux | linux_kernel | >= 5.11 < 5.12.9 | 5.12.9 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8LOW
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: isotp_setsockopt in net/can/isotp.c allows privilege escalation via use-after-free
vendor_redhat·2021-05-12·CVSS 7.8
CVE-2021-32606 [HIGH] CWE-416 kernel: isotp_setsockopt in net/can/isotp.c allows privilege escalation via use-after-free
kernel: isotp_setsockopt in net/can/isotp.c allows privilege escalation via use-after-free
In the Linux kernel 5.11 through 5.12.2, isotp_setsockopt in net/can/isotp.c allows privilege escalation to root by leveraging a use-after-free. (This does not affect earlier versions that lack CAN ISOTP SF_BROADCAST support.)
A flaw was found in the Linux kernel. A use-after-free flaw in isotp_setsockopt leads to arbitrary kernel execution by overwriting the sk_error_report() pointer which can be misused in order to execute a user-controlled ROP chain to gain root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) -
Debian
CVE-2021-32606: linux - In the Linux kernel 5.11 through 5.12.2, isotp_setsockopt in net/can/isotp.c all...
vendor_debian·2021·CVSS 7.8
CVE-2021-32606 [HIGH] CVE-2021-32606: linux - In the Linux kernel 5.11 through 5.12.2, isotp_setsockopt in net/can/isotp.c all...
In the Linux kernel 5.11 through 5.12.2, isotp_setsockopt in net/can/isotp.c allows privilege escalation to root by leveraging a use-after-free. (This does not affect earlier versions that lack CAN ISOTP SF_BROADCAST support.)
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-pp6w-hmm3-7p57: In the Linux kernel 5
ghsa_unreviewed·2022-05-24
CVE-2021-32606 [HIGH] CWE-416 GHSA-pp6w-hmm3-7p57: In the Linux kernel 5
In the Linux kernel 5.11 through 5.12.2, isotp_setsockopt in net/can/isotp.c allows privilege escalation to root by leveraging a use-after-free. (This does not affect earlier versions that lack CAN ISOTP SF_BROADCAST support.)
OSV
CVE-2021-32606: In the Linux kernel 5
osv·2021-05-11·CVSS 7.8
CVE-2021-32606 [HIGH] CVE-2021-32606: In the Linux kernel 5
In the Linux kernel 5.11 through 5.12.2, isotp_setsockopt in net/can/isotp.c allows privilege escalation to root by leveraging a use-after-free. (This does not affect earlier versions that lack CAN ISOTP SF_BROADCAST support.)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2021/05/12/1http://www.openwall.com/lists/oss-security/2021/05/13/2http://www.openwall.com/lists/oss-security/2021/05/14/1http://www.openwall.com/lists/oss-security/2021/05/28/1https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=2b17c400aeb44daf041627722581ade527bb3c1dhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/73D53S4IZFPFQMRABMXXLW4AJK3EULDX/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GI7Z7UBWBGD3ABNIL2DC7RQDCGA4UVQW/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HD3NJBG25AADVGPRC63RX2JOQBMPSWK4/https://security.netapp.com/advisory/ntap-20210625-0001/https://www.openwall.com/lists/oss-security/2021/05/11/16http://www.openwall.com/lists/oss-security/2021/05/12/1http://www.openwall.com/lists/oss-security/2021/05/13/2http://www.openwall.com/lists/oss-security/2021/05/14/1http://www.openwall.com/lists/oss-security/2021/05/28/1https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=2b17c400aeb44daf041627722581ade527bb3c1dhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/73D53S4IZFPFQMRABMXXLW4AJK3EULDX/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GI7Z7UBWBGD3ABNIL2DC7RQDCGA4UVQW/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HD3NJBG25AADVGPRC63RX2JOQBMPSWK4/https://security.netapp.com/advisory/ntap-20210625-0001/https://www.openwall.com/lists/oss-security/2021/05/11/16
2021-05-11
Published