FlawAtlas
Search the atlas
CVE-2021-43267 Critical

CVE-2021-43267

An issue was discovered in net/tipc/crypto.c in the Linux kernel before 5.14.16. The Transparent Inter-Process Communication (TIPC) functionality allows remote attackers to exploit insufficient validation of user-supplied sizes for the MSG_CRYPTO message type.

Exploit probability 57.6%
Published November 2, 2021
Required by Not available
Last source change April 16, 2026

02 / AFFECTED SOFTWARE

Affected packages

Android :linux_kernel:

1 explicit affected versions

Unknown Unknown

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities PUB-A-205243414

In tipc_crypto_key_rcv of net/tipc/crypto.c , there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with System execution privileges needed. User interaction is not needed for exploitation.

View original source
Open Source Vulnerabilities CVE-2021-43267

An issue was discovered in net/tipc/crypto.c in the Linux kernel before 5.14.16. The Transparent Inter-Process Communication (TIPC) functionality allows remote attackers to exploit insufficient validation of user-supplied sizes for the MSG_CRYPTO message type.

View original source

05 / REFERENCES

Further evidence