Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 49

Количество 49

fstec логотип

BDU:2021-04855

больше 5 лет назад

Уязвимость компонента net/sctp/socket.c ядра операционной системы Linux, позволяющая нарушителю повысить свои привилегии

CVSS3: 7
EPSS: Низкий
ubuntu логотип

CVE-2021-23133

больше 5 лет назад

A race condition in Linux kernel SCTP sockets (net/sctp/socket.c) before 5.12-rc8 can lead to kernel privilege escalation from the context of a network service or an unprivileged process. If sctp_destroy_sock is called without sock_net(sk)->sctp.addr_wq_lock then an element is removed from the auto_asconf_splist list without any proper locking. This can be exploited by an attacker with network service privileges to escalate to root or from the context of an unprivileged user directly if a BPF_CGROUP_INET_SOCK_CREATE is attached which denies creation of some SCTP socket.

CVSS3: 6.7
EPSS: Низкий
redhat логотип

CVE-2021-23133

больше 5 лет назад

A race condition in Linux kernel SCTP sockets (net/sctp/socket.c) before 5.12-rc8 can lead to kernel privilege escalation from the context of a network service or an unprivileged process. If sctp_destroy_sock is called without sock_net(sk)->sctp.addr_wq_lock then an element is removed from the auto_asconf_splist list without any proper locking. This can be exploited by an attacker with network service privileges to escalate to root or from the context of an unprivileged user directly if a BPF_CGROUP_INET_SOCK_CREATE is attached which denies creation of some SCTP socket.

CVSS3: 7
EPSS: Низкий
nvd логотип

CVE-2021-23133

больше 5 лет назад

A race condition in Linux kernel SCTP sockets (net/sctp/socket.c) before 5.12-rc8 can lead to kernel privilege escalation from the context of a network service or an unprivileged process. If sctp_destroy_sock is called without sock_net(sk)->sctp.addr_wq_lock then an element is removed from the auto_asconf_splist list without any proper locking. This can be exploited by an attacker with network service privileges to escalate to root or from the context of an unprivileged user directly if a BPF_CGROUP_INET_SOCK_CREATE is attached which denies creation of some SCTP socket.

CVSS3: 6.7
EPSS: Низкий
msrc логотип

CVE-2021-23133

больше 5 лет назад

CVSS3: 7
EPSS: Низкий
debian логотип

CVE-2021-23133

больше 5 лет назад

A race condition in Linux kernel SCTP sockets (net/sctp/socket.c) befo ...

CVSS3: 6.7
EPSS: Низкий
altlinux логотип

ALT-PU-2021-1707

больше 5 лет назад

ALT-PU-2021-1707: package `kernel-image-un-def` update to version 5.11.16-alt1

CVSS3: 7
EPSS: Низкий
altlinux логотип

ALT-PU-2021-1706

больше 5 лет назад

ALT-PU-2021-1706: package `kernel-image-std-def` update to version 5.10.32-alt1

CVSS3: 7.8
EPSS: Низкий
altlinux логотип

ALT-PU-2021-2370

около 5 лет назад

ALT-PU-2021-2370: package `kernel-image-std-debug` update to version 5.10.54-alt1

CVSS3: 8.8
EPSS: Низкий
altlinux логотип

ALT-PU-2021-2678

около 5 лет назад

ALT-PU-2021-2678: package `kernel-image-std-debug` update to version 5.10.61-alt1

CVSS3: 8.8
EPSS: Низкий
altlinux логотип

ALT-PU-2021-2677

около 5 лет назад

ALT-PU-2021-2677: package `kernel-image-std-pae` update to version 5.10.61-alt1

CVSS3: 8.8
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:2460-1

около 5 лет назад

Security update for the Linux Kernel (Live Patch 17 for SLE 12 SP5)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:2384-1

около 5 лет назад

Security update for the Linux Kernel (Live Patch 0 for SLE 15 SP3)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:2366-1

около 5 лет назад

Security update for the Linux Kernel (Live Patch 12 for SLE 15 SP2)

EPSS: Низкий
github логотип

GHSA-hp5q-cmxv-w64v

больше 4 лет назад

A race condition in Linux kernel SCTP sockets (net/sctp/socket.c) before 5.12-rc8 can lead to kernel privilege escalation from the context of a network service or an unprivileged process. If sctp_destroy_sock is called without sock_net(sk)->sctp.addr_wq_lock then an element is removed from the auto_asconf_splist list without any proper locking. This can be exploited by an attacker with network service privileges to escalate to root or from the context of an unprivileged user directly if a BPF_CGROUP_INET_SOCK_CREATE is attached which denies creation of some SCTP socket.

CVSS3: 7
EPSS: Низкий
altlinux логотип

ALT-PU-2021-2672

около 5 лет назад

ALT-PU-2021-2672: package `kernel-image-std-pae` update to version 5.10.61-alt1

CVSS3: 8.8
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:2453-1

около 5 лет назад

Security update for the Linux Kernel (Live Patch 12 for SLE 12 SP5)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:2387-1

около 5 лет назад

Security update for the Linux Kernel (Live Patch 5 for SLE 15 SP2)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:2361-1

около 5 лет назад

Security update for the Linux Kernel (Live Patch 10 for SLE 15 SP2)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:2332-1

около 5 лет назад

Security update for the Linux Kernel (Live Patch 15 for SLE 15 SP1)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2021-04855

Уязвимость компонента net/sctp/socket.c ядра операционной системы Linux, позволяющая нарушителю повысить свои привилегии

CVSS3: 7
0%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2021-23133

A race condition in Linux kernel SCTP sockets (net/sctp/socket.c) before 5.12-rc8 can lead to kernel privilege escalation from the context of a network service or an unprivileged process. If sctp_destroy_sock is called without sock_net(sk)->sctp.addr_wq_lock then an element is removed from the auto_asconf_splist list without any proper locking. This can be exploited by an attacker with network service privileges to escalate to root or from the context of an unprivileged user directly if a BPF_CGROUP_INET_SOCK_CREATE is attached which denies creation of some SCTP socket.

CVSS3: 6.7
0%
Низкий
больше 5 лет назад
redhat логотип
CVE-2021-23133

A race condition in Linux kernel SCTP sockets (net/sctp/socket.c) before 5.12-rc8 can lead to kernel privilege escalation from the context of a network service or an unprivileged process. If sctp_destroy_sock is called without sock_net(sk)->sctp.addr_wq_lock then an element is removed from the auto_asconf_splist list without any proper locking. This can be exploited by an attacker with network service privileges to escalate to root or from the context of an unprivileged user directly if a BPF_CGROUP_INET_SOCK_CREATE is attached which denies creation of some SCTP socket.

CVSS3: 7
0%
Низкий
больше 5 лет назад
nvd логотип
CVE-2021-23133

A race condition in Linux kernel SCTP sockets (net/sctp/socket.c) before 5.12-rc8 can lead to kernel privilege escalation from the context of a network service or an unprivileged process. If sctp_destroy_sock is called without sock_net(sk)->sctp.addr_wq_lock then an element is removed from the auto_asconf_splist list without any proper locking. This can be exploited by an attacker with network service privileges to escalate to root or from the context of an unprivileged user directly if a BPF_CGROUP_INET_SOCK_CREATE is attached which denies creation of some SCTP socket.

CVSS3: 6.7
0%
Низкий
больше 5 лет назад
msrc логотип
CVSS3: 7
0%
Низкий
больше 5 лет назад
debian логотип
CVE-2021-23133

A race condition in Linux kernel SCTP sockets (net/sctp/socket.c) befo ...

CVSS3: 6.7
0%
Низкий
больше 5 лет назад
altlinux логотип
ALT-PU-2021-1707

ALT-PU-2021-1707: package `kernel-image-un-def` update to version 5.11.16-alt1

CVSS3: 7
больше 5 лет назад
altlinux логотип
ALT-PU-2021-1706

ALT-PU-2021-1706: package `kernel-image-std-def` update to version 5.10.32-alt1

CVSS3: 7.8
больше 5 лет назад
altlinux логотип
ALT-PU-2021-2370

ALT-PU-2021-2370: package `kernel-image-std-debug` update to version 5.10.54-alt1

CVSS3: 8.8
около 5 лет назад
altlinux логотип
ALT-PU-2021-2678

ALT-PU-2021-2678: package `kernel-image-std-debug` update to version 5.10.61-alt1

CVSS3: 8.8
около 5 лет назад
altlinux логотип
ALT-PU-2021-2677

ALT-PU-2021-2677: package `kernel-image-std-pae` update to version 5.10.61-alt1

CVSS3: 8.8
около 5 лет назад
suse-cvrf логотип
SUSE-SU-2021:2460-1

Security update for the Linux Kernel (Live Patch 17 for SLE 12 SP5)

0%
Низкий
около 5 лет назад
suse-cvrf логотип
SUSE-SU-2021:2384-1

Security update for the Linux Kernel (Live Patch 0 for SLE 15 SP3)

0%
Низкий
около 5 лет назад
suse-cvrf логотип
SUSE-SU-2021:2366-1

Security update for the Linux Kernel (Live Patch 12 for SLE 15 SP2)

0%
Низкий
около 5 лет назад
github логотип
GHSA-hp5q-cmxv-w64v

A race condition in Linux kernel SCTP sockets (net/sctp/socket.c) before 5.12-rc8 can lead to kernel privilege escalation from the context of a network service or an unprivileged process. If sctp_destroy_sock is called without sock_net(sk)->sctp.addr_wq_lock then an element is removed from the auto_asconf_splist list without any proper locking. This can be exploited by an attacker with network service privileges to escalate to root or from the context of an unprivileged user directly if a BPF_CGROUP_INET_SOCK_CREATE is attached which denies creation of some SCTP socket.

CVSS3: 7
0%
Низкий
больше 4 лет назад
altlinux логотип
ALT-PU-2021-2672

ALT-PU-2021-2672: package `kernel-image-std-pae` update to version 5.10.61-alt1

CVSS3: 8.8
около 5 лет назад
suse-cvrf логотип
SUSE-SU-2021:2453-1

Security update for the Linux Kernel (Live Patch 12 for SLE 12 SP5)

около 5 лет назад
suse-cvrf логотип
SUSE-SU-2021:2387-1

Security update for the Linux Kernel (Live Patch 5 for SLE 15 SP2)

около 5 лет назад
suse-cvrf логотип
SUSE-SU-2021:2361-1

Security update for the Linux Kernel (Live Patch 10 for SLE 15 SP2)

около 5 лет назад
suse-cvrf логотип
SUSE-SU-2021:2332-1

Security update for the Linux Kernel (Live Patch 15 for SLE 15 SP1)

около 5 лет назад

Уязвимостей на страницу