Tracker / CVE-2021-3609
CVE-2021-3609
High 7.0
.A flaw was found in the CAN BCM networking protocol in the Linux kernel, where a local attacker can abuse a flaw in the CAN subsystem to corrupt memory, crash the system or escalate privileges. This race condition in net/can/bcm.c in the Linux kernel allows for local privilege escalation to root.
Affected products and versions
| linux | linux_kernel · 2.6.25 → 4.4.276 |
|---|---|
| linux | linux_kernel · 4.10 → 4.14.240 |
| linux | linux_kernel · 4.15 → 4.19.198 |
| linux | linux_kernel · 4.20 → 5.4.132 |
| linux | linux_kernel · 4.5 → 4.9.276 |
| linux | linux_kernel · 5.11 → 5.12.17 |
| linux | linux_kernel · 5.13 → 5.13.2 |
| linux | linux_kernel · 5.5.0 → 5.10.50 |
| netapp | h300e_firmware |
| netapp | h300s_firmware |
| netapp | h410c_firmware |
| netapp | h410s_firmware |
| netapp | h500e_firmware |
| netapp | h500s_firmware |
| netapp | h610c_firmware |
| netapp | h610s_firmware |
| netapp | h615c_firmware |
| netapp | h700e_firmware |
| netapp | h700s_firmware |
| redhat | 3scale_api_management |
| redhat | build_of_quarkus |
| redhat | codeready_linux_builder_eus |
| redhat | codeready_linux_builder_for_power_little_endian_eus |
| redhat | enterprise_linux_aus |
| redhat | enterprise_linux_eus |
| redhat | enterprise_linux_for_ibm_z_systems_eus |
| redhat | enterprise_linux_for_ibm_z_systems_eus_s390x |
| redhat | enterprise_linux_for_power_little_endian_eus |
| redhat | enterprise_linux_for_real_time |
| redhat | enterprise_linux_for_real_time_for_nfv |
| redhat | enterprise_linux_for_real_time_for_nfv_tus |
| redhat | enterprise_linux_for_real_time_tus |
| redhat | enterprise_linux_server_aus |
| redhat | enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions |
| redhat | enterprise_linux_server_tus |
| redhat | enterprise_linux_server_update_services_for_sap_solutions |
| redhat | openshift_container_platform |
| redhat | virtualization |
| redhat | virtualization_host |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.