CVE-2021-32606
HIGHLinux Kernel 5.11-5.12.2 - Use-After-Free in CAN ISOTP Setsockopt
Title source: llmDescription
In the Linux kernel 5.11 through 5.12.2, isotp_setsockopt in net/can/isotp.c allows privilege escalation to root by leveraging a use-after-free. (This does not affect earlier versions that lack CAN ISOTP SF_BROADCAST support.)
References (10)
Core 10
Core References
Mailing List, Third Party Advisory mailing-list
http://www.openwall.com/lists/oss-security/2021/05/12/1
Mailing List, Third Party Advisory mailing-list
http://www.openwall.com/lists/oss-security/2021/05/13/2
Mailing List, Third Party Advisory mailing-list
http://www.openwall.com/lists/oss-security/2021/05/14/1
Mailing List, Third Party Advisory vendor-advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HD3NJBG25AADVGPRC63RX2JOQBMPSWK4/
Mailing List, Third Party Advisory vendor-advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GI7Z7UBWBGD3ABNIL2DC7RQDCGA4UVQW/
Mailing List, Third Party Advisory vendor-advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/73D53S4IZFPFQMRABMXXLW4AJK3EULDX/
Mailing List, Patch, Third Party Advisory mailing-list
http://www.openwall.com/lists/oss-security/2021/05/28/1
Third Party Advisory
https://security.netapp.com/advisory/ntap-20210625-0001/
Mailing List, Third Party Advisory
https://www.openwall.com/lists/oss-security/2021/05/11/16
Scores
CVSS v3
7.8
EPSS
0.0042
EPSS Percentile
33.6%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-416
Status
published
Products (4)
fedoraproject/fedora
32
fedoraproject/fedora
33
fedoraproject/fedora
34
linux/linux_kernel
5.11 - 5.12.9
Published
May 11, 2021
Tracked Since
Feb 18, 2026