CVE-2021-47591

MEDIUM

Linux Kernel 5.13-5.15.10 - Null Pointer Dereference in MPTCP TCP_ULP Setsockopt

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: mptcp: remove tcp ulp setsockopt support TCP_ULP setsockopt cannot be used for mptcp because its already used internally to plumb subflow (tcp) sockets to the mptcp layer. syzbot managed to trigger a crash for mptcp connections that are in fallback mode: KASAN: null-ptr-deref in range [0x0000000000000020-0x0000000000000027] CPU: 1 PID: 1083 Comm: syz-executor.3 Not tainted 5.16.0-rc2-syzkaller #0 RIP: 0010:tls_build_proto net/tls/tls_main.c:776 [inline] [..] __tcp_set_ulp net/ipv4/tcp_ulp.c:139 [inline] tcp_set_ulp+0x428/0x4c0 net/ipv4/tcp_ulp.c:160 do_tcp_setsockopt+0x455/0x37c0 net/ipv4/tcp.c:3391 mptcp_setsockopt+0x1b47/0x2400 net/mptcp/sockopt.c:638 Remove support for TCP_ULP setsockopt.

Scores

CVSS v3 5.5
EPSS 0.0021
EPSS Percentile 10.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-476
Status published
Products (8)
Linux/Linux < 5.13
Linux/Linux 5.13
Linux/Linux 5.15.11 - 5.15.*
Linux/Linux 5.16
Linux/Linux d9e4c129181004ec94b315b0c9db5eeb09da75e6 - 3de0c86d42f841d1d64f316cd949e65c566f0734
Linux/Linux d9e4c129181004ec94b315b0c9db5eeb09da75e6 - 404cd9a22150f24acf23a8df2ad0c094ba379f57
linux/linux_kernel 5.16 rc1 (5 CPE variants)
linux/linux_kernel 5.13 - 5.15.11
Published Jun 19, 2024
Tracked Since Feb 18, 2026