CVE-2021-3573Race Condition in Kernel

Severity
6.4MEDIUMNVD
OSV7.8OSV5.5OSV4.2
EPSS
0.0%
top 91.77%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 13
Latest updateSep 24

Description

A use-after-free in function hci_sock_bound_ioctl() of the Linux kernel HCI subsystem was found in the way user calls ioct HCIUNBLOCKADDR or other way triggers race condition of the call hci_unregister_dev() together with one of the calls hci_sock_blacklist_add(), hci_sock_blacklist_del(), hci_get_conn_info(), hci_get_auth_info(). A privileged local user could use this flaw to crash the system or escalate their privileges on the system. This flaw affects the Linux kernel versions prior to 5.13-r

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 0.5 | Impact: 5.9

Affected Packages7 packages

NVDlinux/linux_kernel< 5.13+1
Debianlinux/linux_kernel< 5.10.46-1+3
Ubuntulinux/linux_kernel< 4.15.0-154.161+2
CVEListV5linux/linux_kernelkernel 5.13-rc5
debiandebian/linux< linux 5.10.46-1 (bookworm)

Also affects: Enterprise Linux 6.0, 7.0, 8.0, Fedora 34

Patches

🔴Vulnerability Details

10
GHSA
GHSA-73pg-2qfc-2cfm: A use-after-free in function hci_sock_bound_ioctl() of the Linux kernel HCI subsystem was found in the way user calls ioct HCIUNBLOCKADDR or other way2022-05-24
OSV
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities2022-03-22
OSV
linux-aws-5.8, linux-azure-5.8, linux-gcp-5.8, linux-oracle-5.8 vulnerabilities2021-08-24
OSV
linux, linux-aws, linux-aws-hwe, linux-azure, linux-azure-4.15, linux-gcp, linux-gcp-4.15, linux-hwe, linux-kvm, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities2021-08-24
OSV
linux, linux-aws, linux-azure, linux-gcp, linux-hwe-5.11, linux-kvm, linux-oracle, linux-raspi vulnerabilities2021-08-18

📋Vendor Advisories

9
Ubuntu
Linux kernel vulnerabilities2022-03-22
Ubuntu
Linux kernel vulnerabilities2021-08-24
Ubuntu
Linux kernel vulnerabilities2021-08-24
Ubuntu
Linux kernel vulnerabilities2021-08-18
Ubuntu
Linux kernel vulnerabilities2021-08-18

📄Research Papers

1
arXiv
KernJC: Automated Vulnerable Environment Generation for Linux Kernel Vulnerabilities2024-09-24
CVE-2021-3573 — Race Condition in Linux Kernel | cvebase