Race Condition Affecting kernel-docs package, versions <4.12.14-150.75.1


Severity

Recommended
medium

Based on SUSE Linux Enterprise Server security rating.

Threat Intelligence

EPSS
0.08% (35th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-SLES150-KERNELDOCS-2675151
  • published14 Apr 2022
  • disclosed21 Jul 2021

Introduced: 21 Jul 2021

CVE-2021-23133  (opens in a new tab)
CWE-362  (opens in a new tab)

How to fix?

Upgrade SLES:15.0 kernel-docs to version 4.12.14-150.75.1 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream kernel-docs package and not the kernel-docs package as distributed by SLES. See How to fix? for SLES:15.0 relevant fixed versions and status.

A race condition in Linux kernel SCTP sockets (net/sctp/socket.c) before 5.12-rc8 can lead to kernel privilege escalation from the context of a network service or an unprivileged process. If sctp_destroy_sock is called without sock_net(sk)->sctp.addr_wq_lock then an element is removed from the auto_asconf_splist list without any proper locking. This can be exploited by an attacker with network service privileges to escalate to root or from the context of an unprivileged user directly if a BPF_CGROUP_INET_SOCK_CREATE is attached which denies creation of some SCTP socket.

References

CVSS Scores

version 3.1