cbcvebase.
CVE-2021-47309
published 2024-05-21

CVE-2021-47309: In the Linux kernel, the following vulnerability has been resolved: net: validate lwtstate->data before returning from skb_tunnel_info() skb_tunnel_info()…

PriorityP431high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.25%
16.1th percentile
In the Linux kernel, the following vulnerability has been resolved: net: validate lwtstate->data before returning from skb_tunnel_info() skb_tunnel_info() returns pointer of lwtstate->data as ip_tunnel_info type without validation. lwtstate->data can have various types such as mpls_iptunnel_encap, etc and these are not compatible. So skb_tunnel_info() should validate before returning that pointer. Splat looks like: BUG: KASAN: slab-out-of-bounds in vxlan_get_route+0x418/0x4b0 [vxlan] Read of size 2 at addr ffff888106ec2698 by task ping/811 CPU: 1 PID: 811 Comm: ping Not tainted 5.13.0+ #1195 Call Trace: dump_stack_lvl+0x56/0x7b print_address_description.constprop.8.cold.13+0x13/0x2ee ? vxlan_get_route+0x418/0x4b0 [vxlan] ? vxlan_get_route+0x418/0x4b0 [vxlan] kasan_report.cold.14+0x83/0xdf ? vxlan_get_route+0x418/0x4b0 [vxlan] vxlan_get_route+0x418/0x4b0 [vxlan] [ ... ] vxlan_xmit_one+0x148b/0x32b0 [vxlan] [ ... ] vxlan_xmit+0x25c5/0x4780 [vxlan] [ ... ] dev_hard_start_xmit+0x1ae/0x6e0 __dev_queue_xmit+0x1f39/0x31a0 [ ... ] neigh_xmit+0x2f9/0x940 mpls_xmit+0x911/0x1600 [mpls_iptunnel] lwtunnel_xmit+0x18f/0x450 ip_finish_output2+0x867/0x2040 [ ... ]

Affected

22 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.14.6-1 (bookworm)linux 5.14.6-1 (bookworm)
linuxlinux
linuxlinux>= 61adedf3e3f1d3f032c5a6a299978d91eff6d555 < e7f3c9df40515a6c6b46f36c4c94cf48a043f887e7f3c9df40515a6c6b46f36c4c94cf48a043f887
linuxlinux>= 61adedf3e3f1d3f032c5a6a299978d91eff6d555 < b61d327cd3cc5ea591f3bf751dd11e034f388bb5b61d327cd3cc5ea591f3bf751dd11e034f388bb5
linuxlinux>= 61adedf3e3f1d3f032c5a6a299978d91eff6d555 < 83bdcfbd968bcc91a0632b7b625e4a9b0cba5e0d83bdcfbd968bcc91a0632b7b625e4a9b0cba5e0d
linuxlinux>= 61adedf3e3f1d3f032c5a6a299978d91eff6d555 < 8bb1589c89e61e3b182dd546f1021928ebb5c2a68bb1589c89e61e3b182dd546f1021928ebb5c2a6
linuxlinux>= 61adedf3e3f1d3f032c5a6a299978d91eff6d555 < 8aa13a86964cdec4fd969ef677c6614ff068641a8aa13a86964cdec4fd969ef677c6614ff068641a
linuxlinux>= 61adedf3e3f1d3f032c5a6a299978d91eff6d555 < 2179d96ec702cc33ead02a9ce40ece599b8538c52179d96ec702cc33ead02a9ce40ece599b8538c5
linuxlinux>= 61adedf3e3f1d3f032c5a6a299978d91eff6d555 < a915379594f1e045421635c6316d8f3ffa018c58a915379594f1e045421635c6316d8f3ffa018c58
linuxlinux>= 61adedf3e3f1d3f032c5a6a299978d91eff6d555 < 67a9c94317402b826fc3db32afc8f39336803d9767a9c94317402b826fc3db32afc8f39336803d97
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.70-15.10.70-1
linuxlinux_kernel>= 0 < 5.14.6-15.14.6-1
linuxlinux_kernel>= 0 < 5.14.6-15.14.6-1
linuxlinux_kernel>= 0 < 5.14.6-15.14.6-1
linuxlinux_kernel>= 4.10 < 4.14.2414.14.241
linuxlinux_kernel>= 4.15 < 4.19.1994.19.199
linuxlinux_kernel>= 4.20 < 5.4.1355.4.135
linuxlinux_kernel>= 4.3 < 4.4.2774.4.277
linuxlinux_kernel>= 4.5 < 4.9.2774.9.277
linuxlinux_kernel>= 5.11 < 5.13.55.13.5
linuxlinux_kernel>= 5.5 < 5.10.535.10.53

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.