kernel: race condition in net/can/bcm.c leads to local privilege escalation
Published Mar 3, 2022
7.0
HIGHCVSS 3.1
EPSS 0.43%
Description
.A flaw was found in the CAN BCM networking protocol in the Linux kernel, where a local attacker can abuse a flaw in the CAN subsystem to corrupt memory, crash the system or escalate privileges. This race condition in net/can/bcm.c in the Linux kernel allows for local privilege escalation to root.
Affected products
- Vendor n/a Product Kernel Defaultn/a
- Version Affects kernel v2.6.25 to v5.13-rc6StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Kernel | n/a |
|
Configuration 1
- ≥ 2.6.25 · < 4.4.276
- ≥ 4.5 · < 4.9.276
- ≥ 4.10 · < 4.14.240
- ≥ 4.15 · < 4.19.198
- ≥ 4.20 · < 5.4.132
- ≥ 5.5.0 · < 5.10.50
- ≥ 5.11 · < 5.12.17
- ≥ 5.13 · < 5.13.2
Configuration 2
- 2.0
- 1.0
- 8.1
- 8.2
- 8.4
- 8.1
- 8.2
- 8.4
- 4.6
- 4.7
- 4.8
- 4.0
- 4.0
- 8.2
- 8.1
- 8.2
- 8.4
- 8.4
- 8.1
- 8.1
- 8.2
- 8.4
- 8.0
- 8.0
- 8.0
- 8.2
- 8.0
- 8.2
- 8.2
- 8.4
- 8.1
- 8.2
- 8.4
- 8.2
- 8.4
- 8.1
- 8.2
- 8.4
Configuration 3
- n/a
Configuration 4
- n/a
Configuration 5
- n/a
Configuration 6
- n/a
Configuration 7
- n/a
Configuration 8
- n/a
Configuration 9
- n/a
Configuration 10
- n/a
Configuration 11
- n/a
Configuration 12
- n/a
Configuration 13
- n/a
No data.
Red Hat Enterprise Linux 8
kernel-0:4.18.0-305.12.1.el8_4
Fixed · RHSA-2021:3057
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-305.12.1.rt7.84.el8_4
Fixed · RHSA-2021:3088
Red Hat Enterprise Linux 8
kpatch-patch
Fixed · RHSA-2021:3044
Red Hat Enterprise Linux 8.1 Extended Update Support
kernel-0:4.18.0-147.54.2.el8_1
Fixed · RHSA-2021:3444
Red Hat Enterprise Linux 8.1 Extended Update Support
kpatch-patch
Fixed · RHSA-2021:3442
Red Hat Enterprise Linux 8.2 Extended Update Support
kernel-0:4.18.0-193.64.1.el8_2
Fixed · RHSA-2021:3363
Red Hat Enterprise Linux 8.2 Extended Update Support
kernel-rt-0:4.18.0-193.64.1.rt13.115.el8_2
Fixed · RHSA-2021:3375
Red Hat Enterprise Linux 8.2 Extended Update Support
kpatch-patch
Fixed · RHSA-2021:3380
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8
redhat-virtualization-host-0:4.4.7-20210804.0.el8_4
Fixed · RHSA-2021:3235
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-rt
Out of support scope
Red Hat Enterprise Linux 9
kernel
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-305.12.1.el8_4 | Fixed | RHSA-2021:3057 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-305.12.1.rt7.84.el8_4 | Fixed | RHSA-2021:3088 |
| Red Hat Enterprise Linux 8 | kpatch-patch | Fixed | RHSA-2021:3044 |
| Red Hat Enterprise Linux 8.1 Extended Update Support | kernel-0:4.18.0-147.54.2.el8_1 | Fixed | RHSA-2021:3444 |
| Red Hat Enterprise Linux 8.1 Extended Update Support | kpatch-patch | Fixed | RHSA-2021:3442 |
| Red Hat Enterprise Linux 8.2 Extended Update Support | kernel-0:4.18.0-193.64.1.el8_2 | Fixed | RHSA-2021:3363 |
| Red Hat Enterprise Linux 8.2 Extended Update Support | kernel-rt-0:4.18.0-193.64.1.rt13.115.el8_2 | Fixed | RHSA-2021:3375 |
| Red Hat Enterprise Linux 8.2 Extended Update Support | kpatch-patch | Fixed | RHSA-2021:3380 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 | redhat-virtualization-host-0:4.4.7-20210804.0.el8_4 | Fixed | RHSA-2021:3235 |
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Product Security is aware of this issue. Updates will be released as they become available. For Red Hat Virtualization, this flaw is rated Moderate as CAN is not used on host nodes.
Red Hat mitigation
As the CAN module will be auto-loaded when required, its use can be disabled by preventing the module from loading with the following instructions: # echo "install can-bcm /bin/true" >> /etc/modprobe.d/disable-can-bcm.conf The system will need to be restarted if the CAN modules are loaded. In most circumstances, the CAN kernel modules will be unable to be unloaded while any network interfaces are active and the protocol is in use. If the system requires this module to work correctly, this mitigation may not be suitable. If you need further assistance, see KCS article https://access.redhat.com/solutions/41278 or contact Red Hat Global Support Services.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
AV:L/AC:M/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (11 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.43% (0.00431) | 35.08th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.43% (0.00435) | 34.49th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.04% (0.00036) | 6.95th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.04% (0.00042) | 5.07th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.04% (0.00042) | 5.63th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.95% (0.00950) | 32.28th | v2 (v2022.01.01) |
| Feb 13, 2023 | 0.95% (0.00950) | 31.86th | v2 (v2022.01.01) |
| Feb 3, 2023 | 1.55% (0.01547) | 74.40th | v2 (v2022.01.01) |
| Sep 10, 2022 | 0.95% (0.00950) | 30.63th | v2 (v2022.01.01) |
| Apr 1, 2022 | 0.95% (0.00950) | 28.61th | v2 (v2022.01.01) |
| Mar 4, 2022 | 0.95% (0.00950) | 14.24th | v2 (v2022.01.01) |
References (8)
- https://access.redhat.com/security/cve/CVE-2021-3609 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1971651 x_refsource_MISCIssue TrackingThird Party Advisory
- https://github.com/nrb547/kernel-exploitation/blob/main/cve-2021-3609/cve-2021-3609.md x_refsource_MISCExploitTechnical DescriptionThird Party Advisory
- https://github.com/torvalds/linux/commit/d5f9023fa61ee8b94f37a93f08e94b136cf1e463 x_refsource_MISCPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-3609
- https://security.netapp.com/advisory/ntap-20220419-0004/ x_refsource_CONFIRMThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2021-3609
- https://www.openwall.com/lists/oss-security/2021/06/19/1 x_refsource_MISCMailing ListThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2021-3609 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1971651 | x_refsource_MISCIssue TrackingThird Party Advisory | |
| https://github.com/nrb547/kernel-exploitation/blob/main/cve-2021-3609/cve-2021-3609.md | x_refsource_MISCExploitTechnical DescriptionThird Party Advisory | |
| https://github.com/torvalds/linux/commit/d5f9023fa61ee8b94f37a93f08e94b136cf1e463 | x_refsource_MISCPatchThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2021-3609 | ||
| https://security.netapp.com/advisory/ntap-20220419-0004/ | x_refsource_CONFIRMThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2021-3609 | ||
| https://www.openwall.com/lists/oss-security/2021/06/19/1 | x_refsource_MISCMailing ListThird Party Advisory |
Change history (0)
No recorded changes yet.