kernel: use-after-free in function hci_sock_bound_ioctl()
Published Aug 13, 2021
6.7
MEDIUMCVSS 3.1
EPSS 0.37%
Description
A use-after-free in function hci_sock_bound_ioctl() of the Linux kernel HCI subsystem was found in the way user calls ioct HCIUNBLOCKADDR or other way triggers race condition of the call hci_unregister_dev() together with one of the calls hci_sock_blacklist_add(), hci_sock_blacklist_del(), hci_get_conn_info(), hci_get_auth_info(). A privileged local user could use this flaw to crash the system or escalate their privileges on the system. This flaw affects the Linux kernel versions prior to 5.13-rc5.
Affected products
- Vendor n/a Product Kernel Defaultn/a
- Version kernel 5.13-rc5StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Kernel | n/a |
|
Configuration 1
- < 5.13
- 5.13
- 5.13
- 5.13
- 5.13
Configuration 2
- 6.0
- 7.0
- 8.0
Configuration 3
- 34
No data.
Red Hat Enterprise Linux 7
kernel-0:3.10.0-1160.59.1.el7
Fixed · RHSA-2022:0620
Red Hat Enterprise Linux 7
kernel-rt-0:3.10.0-1160.59.1.rt56.1200.el7
Fixed · RHSA-2022:0622
Red Hat Enterprise Linux 8
kernel-0:4.18.0-348.el8
Fixed · RHSA-2021:4356
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-348.rt7.130.el8
Fixed · RHSA-2021:4140
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-alt
Out of support scope
Red Hat Enterprise Linux 9
kernel
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | kernel-0:3.10.0-1160.59.1.el7 | Fixed | RHSA-2022:0620 |
| Red Hat Enterprise Linux 7 | kernel-rt-0:3.10.0-1160.59.1.rt56.1200.el7 | Fixed | RHSA-2022:0622 |
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-348.el8 | Fixed | RHSA-2021:4356 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-348.rt7.130.el8 | Fixed | RHSA-2021:4140 |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-alt | Out of support scope | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue is rated as having a Moderate impact because of the privileges (CAP_NET_ADMIN in initial namespace) required for exploiting the issue.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising easThe required privileges is CAP_NET_ADMIN capabilities. This would require a privileged user with CAP_SYS_ADMIN or root to be able to abuse this flaw reducing its attack space.e of use and deployment, applicability to widespread installation base or stability.
References (8)
- http://www.openwall.com/lists/oss-security/2023/07/02/1 mailing-list
- https://access.redhat.com/security/cve/CVE-2021-3573 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1966578 Issue TrackingThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-26882 Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/bluetooth/bluetooth.git/commit/?id=e305509e678b3a4af2b3cfd410f409f7cdaabb52 PatchVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-3573
- https://www.cve.org/CVERecord?id=CVE-2021-3573
- https://www.openwall.com/lists/oss-security/2021/06/08/2 ExploitMailing ListThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2023/07/02/1 | mailing-list | |
| https://access.redhat.com/security/cve/CVE-2021-3573 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1966578 | Issue TrackingThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-26882 | Advisory | |
| https://git.kernel.org/pub/scm/linux/kernel/git/bluetooth/bluetooth.git/commit/?id=e305509e678b3a4af2b3cfd410f409f7cdaabb52 | PatchVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2021-3573 | ||
| https://www.cve.org/CVERecord?id=CVE-2021-3573 | ||
| https://www.openwall.com/lists/oss-security/2021/06/08/2 | ExploitMailing ListThird Party Advisory |
Change history (0)
No recorded changes yet.