Review reviewHigh

CVE-2021-46999

Linux Linux, linux kernel

In the Linux kernel, the following vulnerability has been resolved: sctp: do asoc update earlier in sctp_sf_do_dupcook_a There's a panic that occurs in a few of envs, the call trace is as below: [] general protection fault, ... 0x29acd70f1000a: 0000 [#1] SMP PTI [] RIP: 0010:sctp_ulpevent_notify_peer_addr_change+0x4b/0x1fa [sctp] [] sctp_assoc_control_transport+0x1b9/0x210 [sctp] [] sctp_do_8_2_transport_strike.isra.16+0x15c/0x220 [sctp] [] sctp_cmd_interpreter.isra.21+0x1231/0x1a10 [sctp] [] sctp_do_sm+0xc3/0x2a0 [sctp] [] sctp_generate_timeout_event+0x81/0xf0 [sctp] This is caused by a tr...

CVSS
7.8
EPSS
0.74%
51.0% percentile
CISA KEV
Not listed
Published
2024.02.28
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.74%
Technical severityCVSS 7.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: sctp: do asoc update earlier in sctp_sf_do_dupcook_a There's a panic that occurs in a few of envs, the call trace is as below: [] general protection fault, ... 0x29acd70f1000a: 0000 [#1] SMP PTI [] RIP: 0010:sctp_ulpevent_notify_peer_addr_change+0x4b/0x1fa [sctp] [] sctp_assoc_control_transport+0x1b9/0x210 [sctp] [] sctp_do_8_2_transport_strike.isra.16+0x15c/0x220 [sctp] [] sctp_cmd_interpreter.isra.21+0x1231/0x1a10 [sctp] [] sctp_do_sm+0xc3/0x2a0 [sctp] [] sctp_generate_timeout_event+0x81/0xf0 [sctp] This is caused by a tr...

Affected product and versions

Product
Linux Linux, linux kernel
Affected versions
>= db8bf823e70f239372c62f13e4eb6f08a1665e8c < d624f2991b977821375fbd56c91b0c91d456a697, >= a204d577be70e0a0a6023cf1b9859c9ebffaeecd < b1b31948c0af44628e43353828453461bb74098f, >= 145cb2f7177d94bc54563ed26027e952ee0ae03c < f01988ecf3654f805282dce2d3bb9afe68d2691e, >= 145cb2f7177d94bc54563ed26027e952ee0ae03c < 61b877bad9bb0d82b7d8841be50872557090a704, >= 145cb2f7177d94bc54563ed26027e952ee0ae03c < 0bfd913c2121b3d553bfd52810fe6061d542d625, >= 145cb2f7177d94bc54563ed26027e952ee0ae03c < 35b4f24415c854cd718ccdf38dbea6297f010aae, >= a5ce8531ea508d270822b2bc6140c6198c8a2a7b, >= 4.19.123 < 4.19.191, >= 5.4.41 < 5.4.120, >= 5.6.13 < 5.7, >= 5.7, >= 5.7 < 5.10.38, >= 5.11 < 5.11.22, >= 5.12 < 5.12.5
Fixed versions
4.19.191, 5.4.120, 5.10.38, 5.11.22, 5.12.5

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, linux kernel and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-416