CVE-2021-23133 Details
Description
A race condition in Linux kernel SCTP sockets (net/sctp/socket.c) before 5.12-rc8 can lead to kernel privilege escalation from the context of a network service or an unprivileged process. If sctp_destroy_sock is called without sock_net(sk)->sctp.addr_wq_lock then an element is removed from the auto_asconf_splist list without any proper locking. This can be exploited by an attacker with network service privileges to escalate to root or from the context of an unprivileged user directly if a BPF_CGROUP_INET_SOCK_CREATE is attached which denies creation of some SCTP socket.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-362 | Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') | [email protected] |
| CWE-362 | Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | < 4.4.269 >= 4.5, < 4.9.269 >= 4.10, < 4.14.233 >= 4.15, < 4.19.191 >= 4.20, < 5.4.119 >= 5.5, < 5.10.37 >= 5.11, < 5.11.21 >= 5.12, < 5.12.4 |
CPE
Remediation
| |
| fedoraproject fedora | 32 33 34 |
CPE
Remediation
| |
| debian debian linux | 9.0 |
CPE
Remediation
| |
| netapp cloud backup | All versions |
CPE
Remediation
| |
| netapp solidfire & hci management node | All versions |
CPE
Remediation
| |
| broadcom brocade fabric operating system | All versions |
CPE
Remediation
| |
| netapp h410c firmware | All versions |
CPE
Remediation
| |
| netapp h410c | All versions |
CPE
Remediation
| |
| netapp h300s firmware | All versions |
CPE
Remediation
| |
| netapp h300s | All versions |
CPE
Remediation
| |
| netapp h500s firmware | All versions |
CPE
Remediation
| |
| netapp h500s | All versions |
CPE
Remediation
| |
| netapp h700s firmware | All versions |
CPE
Remediation
| |
| netapp h700s | All versions |
CPE
Remediation
| |
| netapp h300e firmware | All versions |
CPE
Remediation
| |
| netapp h300e | All versions |
CPE
Remediation
| |
| netapp h500e firmware | All versions |
CPE
Remediation
| |
| netapp h500e | All versions |
CPE
Remediation
| |
| netapp h700e firmware | All versions |
CPE
Remediation
| |
| netapp h700e | All versions |
CPE
Remediation
| |
| netapp h410s firmware | All versions |
CPE
Remediation
| |
| netapp h410s | All versions |
CPE
Remediation
| |
| netapp solidfire baseboard management controller firmware | All versions |
CPE
Remediation
| |
| netapp solidfire baseboard management controller | All versions |
CPE
Remediation
| |
Change History
16 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 30, 2026 | Modified Analysis | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Nov 7, 2023 | CVE Modified | [email protected] |
| Jul 28, 2023 | Reanalysis | [email protected] |
| Oct 7, 2022 | Modified Analysis | [email protected] |
| Jun 23, 2021 | CVE Modified | [email protected] |
| Jun 11, 2021 | CVE Modified | [email protected] |
| May 10, 2021 | CVE Modified | [email protected] |
| May 10, 2021 | CVE Modified | [email protected] |
| May 10, 2021 | CVE Modified | [email protected] |
| Apr 29, 2021 | CVE Modified | [email protected] |
| Apr 27, 2021 | Initial Analysis | [email protected] |
| Apr 27, 2021 | CVE Modified | [email protected] |
| Apr 22, 2021 | CVE Modified | [email protected] |