Back

HIGH

kernel: race condition in net/can/bcm.c leads to local privilege escalation

Published Mar 3, 2022

Description

.A flaw was found in the CAN BCM networking protocol in the Linux kernel, where a local attacker can abuse a flaw in the CAN subsystem to corrupt memory, crash the system or escalate privileges. This race condition in net/can/bcm.c in the Linux kernel allows for local privilege escalation to root.

Affected products

Remediation

Red Hat statement

Red Hat Product Security is aware of this issue. Updates will be released as they become available. For Red Hat Virtualization, this flaw is rated Moderate as CAN is not used on host nodes.

Red Hat mitigation

As the CAN module will be auto-loaded when required, its use can be disabled by preventing the module from loading with the following instructions: # echo "install can-bcm /bin/true" >> /etc/modprobe.d/disable-can-bcm.conf The system will need to be restarted if the CAN modules are loaded. In most circumstances, the CAN kernel modules will be unable to be unloaded while any network interfaces are active and the protocol is in use. If the system requires this module to work correctly, this mitigation may not be suitable. If you need further assistance, see KCS article https://access.redhat.com/solutions/41278 or contact Red Hat Global Support Services.

Metrics

Weaknesses (1)

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Mar 3, 2022
Updated Aug 3, 2024
Reserved Jun 18, 2021
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Jun 19, 2021