CVE-2021-43267: Input Validation
A flaw was discovered in the cryptographic receive code in the Linux kernel's implementation of transparent interprocess communication. An attacker, with the ability to send TIPC messages to the target, can corrupt memory and escalate privileges on the target system.
Other sources
A flaw was found in the Transparent Inter-Process Communication (TIPC) functionality in the Linux kernel. This flaw can allow an attacker able to send MSGCRYPTO messages to one of the interconnected nodes to exploit insufficient validation of user-supplied key sizes resulting in memory corruption and potentially privilege escalation.
References:
https://github.com/torvalds/linux/commit/fa40d9734a57bcbfa79a280189799f76c88f7bb0 https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.14.16 https://thehackernews.com/2021/11/critical-rce-vulnerability-reported-in.html
— Red Hat
An issue was discovered in net/tipc/crypto.c in the Linux kernel before 5.14.16. The Transparent Inter-Process Communication (TIPC) functionality allows remote attackers to exploit insufficient validation of user-supplied sizes for the MSGCRYPTO message type.
Affected Software
Remediation
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2021-43267?
CVE-2021-43267 has a high severity rating due to its ability to allow an attacker to corrupt memory and escalate privileges.
How do I fix CVE-2021-43267?
To remediate CVE-2021-43267, update to the specified secure versions of the Linux kernel as indicated in the affected software section.
Which versions of the Linux kernel are affected by CVE-2021-43267?
CVE-2021-43267 affects Linux kernel versions prior to 5.10.77 and between 5.11 and 5.14.16, as well as specific Red Hat kernel versions.
Can CVE-2021-43267 be exploited remotely?
Yes, CVE-2021-43267 can be exploited remotely if an attacker can send TIPC messages to the vulnerable system.
What types of systems are impacted by CVE-2021-43267?
CVE-2021-43267 impacts various Linux distributions including specific versions of Red Hat, Fedora, and Debian.