CVE-2021-47293

HIGH

Linux Kernel 4.9-4.19.199 - Packet Corruption via skbmod Action on Non-Ethernet Packets

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: net/sched: act_skbmod: Skip non-Ethernet packets Currently tcf_skbmod_act() assumes that packets use Ethernet as their L2 protocol, which is not always the case. As an example, for CAN devices: $ ip link add dev vcan0 type vcan $ ip link set up vcan0 $ tc qdisc add dev vcan0 root handle 1: htb $ tc filter add dev vcan0 parent 1: protocol ip prio 10 \ matchall action skbmod swap mac Doing the above silently corrupts all the packets. Do not perform skbmod actions for non-Ethernet packets.

Scores

CVSS v3 7.8
EPSS 0.0023
EPSS Percentile 14.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (14)
Linux/Linux < 4.9
Linux/Linux 4.19.199 - 4.19.*
Linux/Linux 4.9
Linux/Linux 5.10.54 - 5.10.*
Linux/Linux 5.13.6 - 5.13.*
Linux/Linux 5.14
Linux/Linux 5.4.136 - 5.4.*
Linux/Linux 86da71b57383d40993cb90baafb3735cffe5d800 - 071729150be9e1d1b851b70efb6d91ee9269d57b
Linux/Linux 86da71b57383d40993cb90baafb3735cffe5d800 - 34f1e1f657fae2891b485a3b2b95fe4d2aef9f0d
Linux/Linux 86da71b57383d40993cb90baafb3735cffe5d800 - 727d6a8b7ef3d25080fad228b2c4a1d4da5999c6
... and 4 more
Published May 21, 2024
Tracked Since Feb 18, 2026