Assessment
Why it matters
EPSS is 0.5%; technical severity is CVSS 7.0.
A race condition in Linux kernel SCTP sockets (net/sctp/socket.c) before 5.12-rc8 can lead to kernel privilege escalation from the context of a network service or an unprivileged process. If sctp_destroy_sock is called without sock_net(sk)->sctp.addr_wq_lock then an element is removed from the auto_asconf_splist list without any proper locking. This can be exploited by an attacker with network service privileges to escalate to root or from the context of an unprivileged user directly if a BPF_CGROUP_INET_SOCK_CREATE is attached which denies creation of some SCTP socket.
Who should care
- Teams operating Brocade Fabric Operating System, Debian Linux, Fedora +12 more
- Vulnerability and exposure management teams
- Security operations teams monitoring exploitation activity
Response plan
What I would do
- Confirm whether Brocade Fabric Operating System, Debian Linux, Fedora +12 more is present in the environment.
- Identify affected versions and establish whether vulnerable services are exposed or reachable.
- Debian Mitigation guidance Msg00019
- Review relevant security telemetry for evidence of attempted or successful exploitation.
- Document the remediation decision and track it to verified completion.
Treatment intelligence
Remediation intelligence
Vendor sources are listed before government and third-party guidance. Confirm product applicability and change prerequisites before deployment.
Patch
- Openwall Security patchOpenwallVerification pending ↗
- Openwall Security patchOpenwallVerification pending ↗
- Openwall Security patchOpenwallVerification pending ↗
- Openwall Security patchOpenwallVerification pending ↗
- Git Kernel Security patch CommitGit KernelVerification pending ↗
- Openwall Security patchOpenwallVerification pending ↗
Technical details
- CVSS vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- CWE
- CWE-362
- Affected versions
- Broadcom Brocade Fabric Operating System (Version -); Debian Debian Linux (Version 9.0); Fedoraproject Fedora (Version 32 | Version 33 | Version 34); Linux Linux Kernel (End Excluding 4.4.269 | Start Including 4.5, End Excluding 4.9.269 | Start Including 4.10, End Excluding 4.14.233 | Start Including 4.15, End Excluding 4.19.191); Netapp Cloud Backup (Version -); Netapp H300e Firmware (Version -); Netapp H300s Firmware (Version -); Netapp H410c Firmware (Version -)
- Fixed versions
- Linux Linux Kernel (Fixed from 4.4.269, 4.9.269, 4.14.233, 4.19.191, 5.4.119, 5.10.37, 5.11.21, 5.12.4)
- Published
- 22 April 2021
- Attack vector
- Local
- Privileges required
- Low
- User interaction
- None
Signal timeline
- CVE published
- Latest EPSS score: 0.5%
- Signal calculated at 11