CVE-2021-32606

Source
https://cve.org/CVERecord?id=CVE-2021-32606
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-32606.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2021-32606
Downstream
Related
Published
2021-05-11T23:15:09.013Z
Modified
2026-02-11T13:17:58.549721Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

In the Linux kernel 5.11 through 5.12.2, isotpsetsockopt in net/can/isotp.c allows privilege escalation to root by leveraging a use-after-free. (This does not affect earlier versions that lack CAN ISOTP SFBROADCAST support.)

References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
2b17c400aeb44daf041627722581ade527bb3c1d
Introduced
f40ddce88593482919761f74910f42f4b84c004b
Fixed
2b17c400aeb44daf041627722581ade527bb3c1d

Affected versions

v5.*
v5.11
v5.12
v5.12-rc1
v5.12-rc1-dontuse
v5.12-rc2
v5.12-rc3
v5.12-rc4
v5.12-rc5
v5.12-rc6
v5.12-rc7
v5.12-rc8

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-32606.json"
vanir_signatures
[
    {
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@2b17c400aeb44daf041627722581ade527bb3c1d",
        "digest": {
            "length": 1890.0,
            "function_hash": "325796058127547058737393758674167113078"
        },
        "deprecated": false,
        "signature_type": "Function",
        "target": {
            "function": "isotp_bind",
            "file": "net/can/isotp.c"
        },
        "signature_version": "v1",
        "id": "CVE-2021-32606-0bb16302"
    },
    {
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@2b17c400aeb44daf041627722581ade527bb3c1d",
        "digest": {
            "length": 1570.0,
            "function_hash": "178351634179645973075945367188542698160"
        },
        "deprecated": false,
        "signature_type": "Function",
        "target": {
            "function": "isotp_setsockopt",
            "file": "net/can/isotp.c"
        },
        "signature_version": "v1",
        "id": "CVE-2021-32606-554276a5"
    },
    {
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@2b17c400aeb44daf041627722581ade527bb3c1d",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "206258191537381148782306737467334455475",
                "339310290207284391351575267491940163070",
                "125355207294223673688949841291948236615",
                "13106708059456615052955788072324102981",
                "274441479055418857829916628059110624405",
                "52606388843711140853618511041108152289",
                "47909065737851706869810467475358607174",
                "119542211134361245552350197473664938579",
                "70984518179335315948060081143783091837",
                "33446153231759098592494074706243025690",
                "147775312228265006141643704595701316382",
                "256955766270272755680803020859548537785",
                "67439880968770644703525546353058406775",
                "140632992364741861965357145497980819618",
                "20855232266760963797482295681223900604",
                "191100839513187981545932800874814804692",
                "10912825399951420161626825931331523973",
                "127464637369708110111760227454944726739",
                "271875924933837088682353660105009807571",
                "338397545915768174909247416519456549738",
                "260995741276042585764586280557799280129",
                "298453109283091345228381809173753257212",
                "92178005882122872301179243602506353315",
                "90456997157411085126506558314233352580",
                "1518836363161544451128586341977665452",
                "296930218701986055412858541396097395241",
                "36785381531586714458241109482492480755",
                "279285194137466281145089752791954696857",
                "222522047708411117411324796161180572634",
                "192305006014186671783759949045754530228"
            ]
        },
        "deprecated": false,
        "signature_type": "Line",
        "target": {
            "file": "net/can/isotp.c"
        },
        "signature_version": "v1",
        "id": "CVE-2021-32606-baf5fce9"
    }
]