CVE-2021-43267

Related Vulnerabilities: CVE-2021-43267  

An issue was discovered in net/tipc/crypto.c in the Linux kernel before 5.14.16. The Transparent Inter-Process Communication (TIPC) functionality allows remote attackers to exploit insufficient validation of user-supplied sizes for the MSG_CRYPTO message type.

Description

The MITRE CVE dictionary describes this issue as:

An issue was discovered in net/tipc/crypto.c in the Linux kernel before 5.14.16. The Transparent Inter-Process Communication (TIPC) functionality allows remote attackers to exploit insufficient validation of user-supplied sizes for the MSG_CRYPTO message type.

Additional Information

  • Bugzilla 2020362: CVE-2021-43267 kernel: Insufficient validation of user-supplied sizes for the MSG_CRYPTO message type
  • CWE-20: Improper Input Validation
  • FAQ: Frequently asked questions about CVE-2021-43267