9.8
CVSSv3

CVE-2021-43267

Published: 02/11/2021 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

An issue exists in net/tipc/crypto.c in the Linux kernel prior to 5.14.16. The Transparent Inter-Process Communication (TIPC) functionality allows remote malicious users to exploit insufficient validation of user-supplied sizes for the MSG_CRYPTO message type.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

linux linux kernel

fedoraproject fedora 34

fedoraproject fedora 35

netapp h300s_firmware -

netapp h500s_firmware -

netapp h700s_firmware -

netapp h300e_firmware -

netapp h500e_firmware -

netapp h700e_firmware -

netapp h410s_firmware -

Vendor Advisories

An issue was discovered in net/tipc/cryptoc in the Linux kernel before 51416 The Transparent Inter-Process Communication (TIPC) functionality allows remote attackers to exploit insufficient validation of user-supplied sizes for the MSG_CRYPTO message type ...
ALAS2LIVEPATCH-2021-074 Amazon Linux 2 Security Advisory: ALASLIVEPATCH-2021-074 Advisory Release Date: 2021-12-02 19:15 P ...
ALAS2LIVEPATCH-2021-073 Amazon Linux 2 Security Advisory: ALASLIVEPATCH-2021-073 Advisory Release Date: 2021-12-02 19:15 P ...
A race condition accessing file object in the Linux kernel OverlayFS subsystem was found in the way users do rename in specific way with OverlayFS A local user could use this flaw to crash the system (CVE-2021-20321) A flaw was found in the Linux kernel A memory leak in the ccp-ops crypto driver can allow attackers to cause a denial of service ...
An issue was discovered in net/tipc/cryptoc in the Linux kernel before 51416 The Transparent Inter-Process Communication (TIPC) functionality allows remote attackers to exploit insufficient validation of user-supplied sizes for the MSG_CRYPTO message type ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> CVE-2022-0435: Remote Stack Overflow in Linux Kernel TIPC Module since 48 (net/tipc) <!--X-Subject-Header-End--> <!--X-Head-o ...

Github Repositories

trusty poc Provide it to legitimate people

CVE-2021-43267-POC trusty poc Provide it to legitimate people

Challenge Problem #1 - Linux Kernel

AIxCC Linux Kernel CP Exemplar Release 01 This Challenge Project Exemplar release aims to provide competitors with a Challenge Project that resembles the same structure and interface that will exist for all Challenge Projects during the competition This exemplar has been developed and tested with the following versions: Ubuntu 220404 LTS Docker version 2600 Note: The con

Recent Articles

Will they try it for 30 days first? McAfee goes private again in $14bn cash deal
The Register • Iain Thomson in San Francisco • 08 Nov 2021

Get our weekly newsletter Plus: Uncle Sam gets tough on patching, NIST needs you, and more

In brief A consortium of private equity types have stumped up $12bn in cash to acquire what's left of McAfee the company plus another couple of billion to pay off its debts. McAfee has been in and out of the stock market: it last went public in October 2020 with a valuation of $3.6bn. It then spun off its enterprise security business in March for $4bn in another cash deal, and now the consumer side of the business has been snapped up for $14bn total. “This transaction is a testament to McAfeeâ...

Ransomware can mean life or death at hospitals, but DEF CON hackers have a plan
The Register

Topics Security Off-Prem On-Prem Software Offbeat Special Features Vendor Voice Vendor Voice Resources ARPA-H joins the challenge, adds $20M to cash rewards

Interview As ransomware gangs target critical infrastructure – especially hospitals and other healthcare organizations – DARPA has added another government agency partner to its Artificial Intelligence Cyber Challenge (AIxCC). AIxCC is the two-year competition that DARPA announced last summer at Black Hat which challenges teams to build AI-based tools that automatically secure code used in critical infrastructure. The new government agency partner is the Advanced Research Projects Agency for...