CVE-2021-26708
kernel: race conditions caused by wrong locking in net/vmw_vsock/af_vsock.c
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
A local privilege escalation was discovered in the Linux kernel before 5.10.13. Multiple race conditions in the AF_VSOCK implementation are caused by wrong locking in net/vmw_vsock/af_vsock.c. The race conditions were implicitly introduced in the commits that added VSOCK multi-transport support.
Se detectó una escalada de privilegios local en el kernel de Linux versiones anteriores a 5.10.13. Múltiples condiciones de carrera en la implementación de AF_VSOCK son causadas mediante un bloqueo incorrecto en el archivo net/vmw_vsock / af_vsock.c. Las condiciones de carrera se introdujeron implícitamente en las commits que agregaron soporte de transporte múltiple de VSOCK
A flaw was found in the Linux kernel. Wrong locking in the AF_VSOCK socket can cause a local privilege escalation, bypassing SMEP and SMAP. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Red Hat Advanced Cluster Management for Kubernetes 2.2.2 images Red Hat Advanced Cluster Management for Kubernetes provides the capabilities to address common challenges that administrators and site reliability engineers face as they work across a range of public and private cloud environments. Clusters and applications are all visible and managed from a single console-with security policy built in. This advisory contains the container images for Red Hat Advanced Cluster Management for Kubernetes, which fix several bugs and security issues. Issues addressed include code execution, denial of service, integer overflow, and null pointer vulnerabilities.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-02-05 CVE Reserved
- 2021-02-05 CVE Published
- 2021-06-12 First Exploit
- 2024-08-03 CVE Updated
- 2025-03-28 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
- CWE-667: Improper Locking
CAPEC
References (11)
URL | Tag | Source |
---|---|---|
http://www.openwall.com/lists/oss-security/2021/04/09/2 | Mailing List |
|
http://www.openwall.com/lists/oss-security/2022/01/25/14 | Mailing List |
|
URL | Date | SRC |
---|---|---|
https://github.com/azpema/CVE-2021-26708 | 2021-06-12 | |
https://github.com/jordan9001/vsock_poc | 2024-11-12 |
URL | Date | SRC |
---|---|---|
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.13 | 2023-11-09 | |
https://access.redhat.com/security/cve/CVE-2021-26708 | 2021-04-06 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1925588 | 2021-04-06 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Netapp Search vendor "Netapp" | Baseboard Management Controller 500f Firmware Search vendor "Netapp" for product "Baseboard Management Controller 500f Firmware" | < 15.3 Search vendor "Netapp" for product "Baseboard Management Controller 500f Firmware" and version " < 15.3" | - |
Affected
| in | Netapp Search vendor "Netapp" | 500f Search vendor "Netapp" for product "500f" | - | - |
Safe
|
Netapp Search vendor "Netapp" | Baseboard Management Controller A250 Firmware Search vendor "Netapp" for product "Baseboard Management Controller A250 Firmware" | < 15.3 Search vendor "Netapp" for product "Baseboard Management Controller A250 Firmware" and version " < 15.3" | - |
Affected
| in | Netapp Search vendor "Netapp" | A250 Search vendor "Netapp" for product "A250" | - | - |
Safe
|
Netapp Search vendor "Netapp" | Hci H410c Firmware Search vendor "Netapp" for product "Hci H410c Firmware" | - | - |
Affected
| in | Netapp Search vendor "Netapp" | Hci H410c Search vendor "Netapp" for product "Hci H410c" | - | - |
Safe
|
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | >= 5.5 < 5.10.13 Search vendor "Linux" for product "Linux Kernel" and version " >= 5.5 < 5.10.13" | - |
Affected
| ||||||
Netapp Search vendor "Netapp" | Aff Baseboard Management Controller Search vendor "Netapp" for product "Aff Baseboard Management Controller" | - | - |
Affected
| ||||||
Netapp Search vendor "Netapp" | Cloud Backup Search vendor "Netapp" for product "Cloud Backup" | - | - |
Affected
| ||||||
Netapp Search vendor "Netapp" | Fas Baseboard Management Controller Search vendor "Netapp" for product "Fas Baseboard Management Controller" | - | - |
Affected
| ||||||
Netapp Search vendor "Netapp" | Solidfire \& Hci Management Node Search vendor "Netapp" for product "Solidfire \& Hci Management Node" | - | - |
Affected
| ||||||
Netapp Search vendor "Netapp" | Solidfire Baseboard Management Controller Search vendor "Netapp" for product "Solidfire Baseboard Management Controller" | - | - |
Affected
|