Wiz Agents & Workflows are here

CVE-2021-23133
Linux Kernel vulnerability analysis and mitigation

Overview

A race condition vulnerability (CVE-2021-23133) was discovered in Linux kernel SCTP sockets (net/sctp/socket.c) before version 5.12-rc8. The vulnerability was discovered by Or Cohen of Palo Alto Networks and publicly disclosed on April 18, 2021. The issue affects the SCTP socket implementation in the Linux kernel, specifically when sctp_destroy_sock is called without proper locking mechanisms (Openwall).

Technical details

The vulnerability occurs when sctp_destroy_sock is called without sock_net(sk)->sctp.addr_wq_lock being held, allowing an element to be removed from the auto_asconf_splist list without proper locking. This can happen in two scenarios: 1) In sctp_accept, if sctp_sock_migrate fails, or 2) In inet_create or inet6_create, if there is a BPF program attached to BPF_CGROUP_INET_SOCK_CREATE which denies creation of the SCTP socket. The issue was fixed with commit 34e5b01186858b36c4d7c87e1a025071e8e2401f after an initial fix was reverted (OSS Security).

Impact

When successfully exploited, this vulnerability could lead to kernel privilege escalation from the context of a network service or from an unprivileged process. The issue could result in denial of service (system crash), memory corruption, or potentially arbitrary code execution with elevated privileges (Ubuntu Security).

Mitigation and workarounds

The vulnerability was patched in Linux kernel version 5.12-rc8. Multiple distributions have released updates to address this issue, including Ubuntu (versions 5.11.0-22.23 for 21.04, 5.8.0-59.66 for 20.10, and others), Fedora (versions 5.11.16 for Fedora 32, 33, and 34), and Debian (version 4.9.272-1 for Debian 9 stretch) (Ubuntu Security, Debian Security).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-23395CRITICAL9.1
  • Linux KernelLinux Kernel
  • kernel-rt-64k-debug-devel-matched
NoYesMar 25, 2026
CVE-2026-23399MEDIUM6.5
  • Linux KernelLinux Kernel
  • kernel-rt-64k-debug-devel-matched
NoYesMar 28, 2026
CVE-2026-23398MEDIUM6.5
  • Linux KernelLinux Kernel
  • kernel-abi-stablelists
NoYesMar 26, 2026
CVE-2026-23397MEDIUM4.4
  • Linux KernelLinux Kernel
  • kernel-devel
NoYesMar 26, 2026
CVE-2026-31788N/AN/A
  • Linux KernelLinux Kernel
  • kernel-rt-trace-kvm
NoYesMar 25, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management