Fiche vulnérabilité
CVE-2021-3609 : faille élevée linux linux kernel (CVSS 7.0)
Description
.A flaw was found in the CAN BCM networking protocol in the Linux kernel, where a local attacker can abuse a flaw in the CAN subsystem to corrupt memory, crash the system or escalate privileges. This race condition in net/can/bcm.c in the Linux kernel allows for local privilege escalation to root.
En bref
- Sévérité
- Élevée (CVSS 7.0)
- Vecteur CVSS
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 3 mars 2022
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- linux linux kernel
- redhat 3scale api management
- redhat build of quarkus
- redhat codeready linux builder eus
- redhat codeready linux builder for power little endian eus
- redhat openshift container platform
- redhat virtualization
- redhat virtualization host
- redhat enterprise linux aus
- redhat enterprise linux eus
- redhat enterprise linux for ibm z systems eus
- redhat enterprise linux for ibm z systems eus s390x
- redhat enterprise linux for power little endian eus
- redhat enterprise linux for real time
- redhat enterprise linux for real time for nfv
- redhat enterprise linux for real time for nfv tus
- redhat enterprise linux for real time tus
- redhat enterprise linux server aus
- redhat enterprise linux server for power little endian update services for sap solutions
- redhat enterprise linux server tus