CVE-2021-3640

medium
Published 2022-11-15 · Modified 2022-11-18
CVSS v3
VIR risk
5.5

Description

A flaw use-after-free in function sco_sock_sendmsg() of the Linux kernel HCI subsystem was found in the way user calls ioct UFFDIO_REGISTER or other way triggers race condition of the call sco_conn_del() together with the call sco_sock_sendmsg() with the expected controllable faulting memory page. A privileged local user could use this flaw to crash the system or escalate their privileges on the system.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.

OS impact

OSVersionStatusFixed in
redhat rhel9fixed
almalinux almalinux9fixedkernel-rt-debug-core-5.14.0-162.6.1.rt21.168.el9_1.x86_64.rpm
arch archfixed5.14.21.hardened1-1
suse slesaffected
rockylinux rocky8fixed
debian debianbookwormfixed5.15.3-1
debian debianbullseyefixed5.10.84-1
debian debianforkyfixed5.15.3-1
debian debiansidfixed5.15.3-1
debian debiantrixiefixed5.15.3-1

References

💬 Discuss CVE-2021-3640 on VIR Community →

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.