Количество 49
Количество 49
BDU:2021-04855
Уязвимость компонента net/sctp/socket.c ядра операционной системы Linux, позволяющая нарушителю повысить свои привилегии
CVE-2021-23133
A race condition in Linux kernel SCTP sockets (net/sctp/socket.c) before 5.12-rc8 can lead to kernel privilege escalation from the context of a network service or an unprivileged process. If sctp_destroy_sock is called without sock_net(sk)->sctp.addr_wq_lock then an element is removed from the auto_asconf_splist list without any proper locking. This can be exploited by an attacker with network service privileges to escalate to root or from the context of an unprivileged user directly if a BPF_CGROUP_INET_SOCK_CREATE is attached which denies creation of some SCTP socket.
CVE-2021-23133
A race condition in Linux kernel SCTP sockets (net/sctp/socket.c) before 5.12-rc8 can lead to kernel privilege escalation from the context of a network service or an unprivileged process. If sctp_destroy_sock is called without sock_net(sk)->sctp.addr_wq_lock then an element is removed from the auto_asconf_splist list without any proper locking. This can be exploited by an attacker with network service privileges to escalate to root or from the context of an unprivileged user directly if a BPF_CGROUP_INET_SOCK_CREATE is attached which denies creation of some SCTP socket.
CVE-2021-23133
A race condition in Linux kernel SCTP sockets (net/sctp/socket.c) before 5.12-rc8 can lead to kernel privilege escalation from the context of a network service or an unprivileged process. If sctp_destroy_sock is called without sock_net(sk)->sctp.addr_wq_lock then an element is removed from the auto_asconf_splist list without any proper locking. This can be exploited by an attacker with network service privileges to escalate to root or from the context of an unprivileged user directly if a BPF_CGROUP_INET_SOCK_CREATE is attached which denies creation of some SCTP socket.
CVE-2021-23133
CVE-2021-23133
A race condition in Linux kernel SCTP sockets (net/sctp/socket.c) befo ...
ALT-PU-2021-1707
ALT-PU-2021-1707: package `kernel-image-un-def` update to version 5.11.16-alt1
ALT-PU-2021-1706
ALT-PU-2021-1706: package `kernel-image-std-def` update to version 5.10.32-alt1
ALT-PU-2021-2370
ALT-PU-2021-2370: package `kernel-image-std-debug` update to version 5.10.54-alt1
ALT-PU-2021-2678
ALT-PU-2021-2678: package `kernel-image-std-debug` update to version 5.10.61-alt1
ALT-PU-2021-2677
ALT-PU-2021-2677: package `kernel-image-std-pae` update to version 5.10.61-alt1
SUSE-SU-2021:2460-1
Security update for the Linux Kernel (Live Patch 17 for SLE 12 SP5)
SUSE-SU-2021:2384-1
Security update for the Linux Kernel (Live Patch 0 for SLE 15 SP3)
SUSE-SU-2021:2366-1
Security update for the Linux Kernel (Live Patch 12 for SLE 15 SP2)
GHSA-hp5q-cmxv-w64v
A race condition in Linux kernel SCTP sockets (net/sctp/socket.c) before 5.12-rc8 can lead to kernel privilege escalation from the context of a network service or an unprivileged process. If sctp_destroy_sock is called without sock_net(sk)->sctp.addr_wq_lock then an element is removed from the auto_asconf_splist list without any proper locking. This can be exploited by an attacker with network service privileges to escalate to root or from the context of an unprivileged user directly if a BPF_CGROUP_INET_SOCK_CREATE is attached which denies creation of some SCTP socket.
ALT-PU-2021-2672
ALT-PU-2021-2672: package `kernel-image-std-pae` update to version 5.10.61-alt1
SUSE-SU-2021:2453-1
Security update for the Linux Kernel (Live Patch 12 for SLE 12 SP5)
SUSE-SU-2021:2387-1
Security update for the Linux Kernel (Live Patch 5 for SLE 15 SP2)
SUSE-SU-2021:2361-1
Security update for the Linux Kernel (Live Patch 10 for SLE 15 SP2)
SUSE-SU-2021:2332-1
Security update for the Linux Kernel (Live Patch 15 for SLE 15 SP1)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2021-04855 Уязвимость компонента net/sctp/socket.c ядра операционной системы Linux, позволяющая нарушителю повысить свои привилегии | CVSS3: 7 | 0% Низкий | больше 5 лет назад | |
CVE-2021-23133 A race condition in Linux kernel SCTP sockets (net/sctp/socket.c) before 5.12-rc8 can lead to kernel privilege escalation from the context of a network service or an unprivileged process. If sctp_destroy_sock is called without sock_net(sk)->sctp.addr_wq_lock then an element is removed from the auto_asconf_splist list without any proper locking. This can be exploited by an attacker with network service privileges to escalate to root or from the context of an unprivileged user directly if a BPF_CGROUP_INET_SOCK_CREATE is attached which denies creation of some SCTP socket. | CVSS3: 6.7 | 0% Низкий | больше 5 лет назад | |
CVE-2021-23133 A race condition in Linux kernel SCTP sockets (net/sctp/socket.c) before 5.12-rc8 can lead to kernel privilege escalation from the context of a network service or an unprivileged process. If sctp_destroy_sock is called without sock_net(sk)->sctp.addr_wq_lock then an element is removed from the auto_asconf_splist list without any proper locking. This can be exploited by an attacker with network service privileges to escalate to root or from the context of an unprivileged user directly if a BPF_CGROUP_INET_SOCK_CREATE is attached which denies creation of some SCTP socket. | CVSS3: 7 | 0% Низкий | больше 5 лет назад | |
CVE-2021-23133 A race condition in Linux kernel SCTP sockets (net/sctp/socket.c) before 5.12-rc8 can lead to kernel privilege escalation from the context of a network service or an unprivileged process. If sctp_destroy_sock is called without sock_net(sk)->sctp.addr_wq_lock then an element is removed from the auto_asconf_splist list without any proper locking. This can be exploited by an attacker with network service privileges to escalate to root or from the context of an unprivileged user directly if a BPF_CGROUP_INET_SOCK_CREATE is attached which denies creation of some SCTP socket. | CVSS3: 6.7 | 0% Низкий | больше 5 лет назад | |
CVSS3: 7 | 0% Низкий | больше 5 лет назад | ||
CVE-2021-23133 A race condition in Linux kernel SCTP sockets (net/sctp/socket.c) befo ... | CVSS3: 6.7 | 0% Низкий | больше 5 лет назад | |
ALT-PU-2021-1707 ALT-PU-2021-1707: package `kernel-image-un-def` update to version 5.11.16-alt1 | CVSS3: 7 | больше 5 лет назад | ||
ALT-PU-2021-1706 ALT-PU-2021-1706: package `kernel-image-std-def` update to version 5.10.32-alt1 | CVSS3: 7.8 | больше 5 лет назад | ||
ALT-PU-2021-2370 ALT-PU-2021-2370: package `kernel-image-std-debug` update to version 5.10.54-alt1 | CVSS3: 8.8 | около 5 лет назад | ||
ALT-PU-2021-2678 ALT-PU-2021-2678: package `kernel-image-std-debug` update to version 5.10.61-alt1 | CVSS3: 8.8 | около 5 лет назад | ||
ALT-PU-2021-2677 ALT-PU-2021-2677: package `kernel-image-std-pae` update to version 5.10.61-alt1 | CVSS3: 8.8 | около 5 лет назад | ||
SUSE-SU-2021:2460-1 Security update for the Linux Kernel (Live Patch 17 for SLE 12 SP5) | 0% Низкий | около 5 лет назад | ||
SUSE-SU-2021:2384-1 Security update for the Linux Kernel (Live Patch 0 for SLE 15 SP3) | 0% Низкий | около 5 лет назад | ||
SUSE-SU-2021:2366-1 Security update for the Linux Kernel (Live Patch 12 for SLE 15 SP2) | 0% Низкий | около 5 лет назад | ||
GHSA-hp5q-cmxv-w64v A race condition in Linux kernel SCTP sockets (net/sctp/socket.c) before 5.12-rc8 can lead to kernel privilege escalation from the context of a network service or an unprivileged process. If sctp_destroy_sock is called without sock_net(sk)->sctp.addr_wq_lock then an element is removed from the auto_asconf_splist list without any proper locking. This can be exploited by an attacker with network service privileges to escalate to root or from the context of an unprivileged user directly if a BPF_CGROUP_INET_SOCK_CREATE is attached which denies creation of some SCTP socket. | CVSS3: 7 | 0% Низкий | больше 4 лет назад | |
ALT-PU-2021-2672 ALT-PU-2021-2672: package `kernel-image-std-pae` update to version 5.10.61-alt1 | CVSS3: 8.8 | около 5 лет назад | ||
SUSE-SU-2021:2453-1 Security update for the Linux Kernel (Live Patch 12 for SLE 12 SP5) | около 5 лет назад | |||
SUSE-SU-2021:2387-1 Security update for the Linux Kernel (Live Patch 5 for SLE 15 SP2) | около 5 лет назад | |||
SUSE-SU-2021:2361-1 Security update for the Linux Kernel (Live Patch 10 for SLE 15 SP2) | около 5 лет назад | |||
SUSE-SU-2021:2332-1 Security update for the Linux Kernel (Live Patch 15 for SLE 15 SP1) | около 5 лет назад |
Уязвимостей на страницу