CVE-2021-32606: Use After Free
Published May 11, 2021
·Updated
In the Linux kernel 5.11 through 5.12.2, isotpsetsockopt in net/can/isotp.c allows privilege escalation to root by leveraging a use-after-free. (This does not affect earlier versions that lack CAN ISOTP SFBROADCAST support.)
Affected Software
4 affected components
Linux Linux kernel>=5.11<5.12.9
Fedoraproject Fedora=32
Fedoraproject Fedora=33
Fedoraproject Fedora=34
Remediation
Patch Available
Event History
May 11, 2021
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-32606?
CVE-2021-32606 is considered a high severity vulnerability as it allows privilege escalation to root.
2
How do I fix CVE-2021-32606?
To fix CVE-2021-32606, upgrade the Linux kernel to a version greater than 5.12.2 that does not include the vulnerability.
3
Which Linux kernel versions are affected by CVE-2021-32606?
CVE-2021-32606 affects Linux kernel versions 5.11 through 5.12.2.
4
Does CVE-2021-32606 affect earlier versions of the Linux kernel?
No, CVE-2021-32606 does not affect earlier versions that lack CAN ISOTP SF_BROADCAST support.
5
What type of vulnerability is CVE-2021-32606?
CVE-2021-32606 is a use-after-free vulnerability that can be exploited for privilege escalation.