UBUNTU-CVE-2021-43267
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-43267
UBUNTU-CVE-2021-43267
Summary:
Details: An issue was discovered in net/tipc/crypto.c in the Linux kernel before 5.14.16. The Transparent Inter-Process Communication (TIPC) functionality allows remote attackers to exploit insufficient validation of user-supplied sizes for the MSG_CRYPTO message type.
References: https://ubuntu.com/security/CVE-2021-43267, https://git.kernel.org/linus/fa40d9734a57bcbfa79a280189799f76c88f7bb0, https://github.com/torvalds/linux/commit/fa40d9734a57bcbfa79a280189799f76c88f7bb0, https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.14.16, https://www.sentinelone.com/labs/tipc-remote-linux-kernel-heap-overflow-allows-arbitrary-code-execution/, https://ubuntu.com/security/notices/USN-5165-1, https://ubuntu.com/security/notices/USN-5207-1, https://ubuntu.com/security/notices/USN-5208-1, https://ubuntu.com/security/notices/USN-5218-1, https://www.cve.org/CVERecord?id=CVE-2021-43267
Affected packages
Package
Name: linux-hwe-edge
Purl: pkg:deb/ubuntu/[email protected]~16.04.1?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
