CVE-2021-43267Improper Validation of Specified Quantity in Input in Kernel

Severity
9.8CRITICALNVD
OSV7.8OSV4.7OSV4.1
EPSS
72.6%
top 1.23%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 2
Latest updateFeb 14

Description

An issue was discovered in net/tipc/crypto.c in the Linux kernel before 5.14.16. The Transparent Inter-Process Communication (TIPC) functionality allows remote attackers to exploit insufficient validation of user-supplied sizes for the MSG_CRYPTO message type.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages6 packages

NVDlinux/linux_kernel5.105.10.77+1
Debianlinux/linux_kernel< 5.10.84-1+3
debiandebian/linux< linux 5.14.16-1 (bookworm)

Also affects: Fedora 34, 35

Patches

🔴Vulnerability Details

8
GHSA
GHSA-c22h-4v9p-5cx2: An issue was discovered in net/tipc/crypto2022-05-24
OSV
CVE-2021-43267: In tipc_crypto_key_rcv of net/tipc/crypto2022-03-01
OSV
linux-oem-5.13 vulnerabilities2022-01-11
OSV
linux, linux-aws, linux-aws-5.11, linux-azure, linux-azure-5.11, linux-gcp, linux-gcp-5.11, linux-hwe-5.11, linux-kvm, linux-oracle, linux-oracle-5.11, linux-raspi vulnerabilities2022-01-06
OSV
linux-oem-5.10 vulnerabilities2022-01-05

📋Vendor Advisories

8
Palo Alto
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS2024-02-14
Ubuntu
Linux kernel (OEM) vulnerabilities2022-01-11
Ubuntu
Linux kernel vulnerabilities2022-01-06
Ubuntu
Linux kernel (OEM) vulnerabilities2022-01-05
Ubuntu
Linux kernel (OEM) vulnerabilities2021-11-30

🕵️Threat Intelligence

2
Sentinelone
CVE-2021-43267: Remote Linux Kernel Heap Overflow | TIPC Module Allows Arbitrary Code Execution2021-11-04
Sentinelone
CVE-2021-43267: Remote Linux Kernel Heap Overflow | TIPC Module Allows Arbitrary Code Execution2021-11-04
CVE-2021-43267 — Linux Kernel vulnerability | cvebase