imPC@ndo IT

Tracker / CVE-2021-26708

CVE-2021-26708

High 7.0

A local privilege escalation was discovered in the Linux kernel before 5.10.13. Multiple race conditions in the AF_VSOCK implementation are caused by wrong locking in net/vmw_vsock/af_vsock.c. The race conditions were implicitly introduced in the commits that added VSOCK multi-transport support.

Affected products and versions

linux linux_kernel · 5.5 → 5.10.13
netapp aff_baseboard_management_controller
netapp baseboard_management_controller_500f_firmware · … → 15.3
netapp baseboard_management_controller_a250_firmware · … → 15.3
netapp cloud_backup
netapp fas_baseboard_management_controller
netapp hci_h410c_firmware
netapp solidfire_\&_hci_management_node
netapp solidfire_baseboard_management_controller

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References