CVE-2021-3640: Race Condition
A flaw use-after-free in function scosocksendmsg() of the Linux kernel HCI subsystem was found in the way user calls ioct UFFDIOREGISTER or other way triggers race condition of the call scoconndel() together with the call scosocksendmsg() with the expected controllable faulting memory page. A privileged local user could use this flaw to crash the system or escalate their privileges on the system.
Other sources
Unexpected locking behavior leads to a use-after-free vulnerability in function scosocksendmsg() allowing the attacker to inject a malicious payload.
— Red Hat
Affected Software
Remediation
Information
Patch Available
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2021-3640?
The severity of CVE-2021-3640 is rated as medium, posing a potential risk for denial of service or data corruption.
How do I fix CVE-2021-3640?
To fix CVE-2021-3640, upgrade to the recommended versions of the Linux kernel, specifically 0:4.18.0-425.3.1.el8 or higher.
What systems are affected by CVE-2021-3640?
CVE-2021-3640 affects multiple versions of the Linux kernel across various distributions including Red Hat, Ubuntu, and Debian.
Is CVE-2021-3640 a remote exploit?
CVE-2021-3640 is not a remote exploit but rather requires local access to trigger the vulnerability.
What mitigations exist for CVE-2021-3640?
Mitigations for CVE-2021-3640 involve applying the latest kernel updates that address the use-after-free flaw.