CVE-2021-33033
Summary
| CVE | CVE-2021-33033 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-05-14 23:15:09 UTC |
| Updated | 2026-08-05 18:35:52 UTC |
| Description | The Linux kernel before 5.11.14 has a use-after-free in cipso_v4_genopt in net/ipv4/cipso_ipv4.c because the CIPSO and CALIPSO refcounting for the DOI definitions is mishandled, aka CID-ad5d07f4a9cd. This leads to writing an arbitrary value. |
Risk And Classification
Primary CVSS: v3.1 7.8 HIGH from [email protected]
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Problem Types: CWE-416 | n/a
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 2.0 | [email protected] | Primary | 4.6 | AV:L/AC:L/Au:N/C:P/I:P/A:P |
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:L/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Linux | Linux Kernel | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.11.7 | af854a3a-2127-422b-91ae-364da2661108 | cdn.kernel.org | Mailing List, Patch, Vendor Advisory |
| SyzScope - KASAN: use-after-free Read in cipso_v4_genopt | af854a3a-2127-422b-91ae-364da2661108 | sites.google.com | Exploit, Third Party Advisory |
| kernel/git/torvalds/linux.git - Linux kernel source tree | af854a3a-2127-422b-91ae-364da2661108 | git.kernel.org | Mailing List, Patch, Vendor Advisory |
| KASAN: use-after-free Read in cipso_v4_genopt | af854a3a-2127-422b-91ae-364da2661108 | syzkaller.appspot.com | Exploit, Mailing List, Third Party Advisory |
| kernel/git/torvalds/linux.git - Linux kernel source tree | af854a3a-2127-422b-91ae-364da2661108 | git.kernel.org | Mailing List, Patch, Vendor Advisory |
| cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.11.14 | af854a3a-2127-422b-91ae-364da2661108 | cdn.kernel.org | Mailing List, Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159304 Oracle Enterprise Linux Security Update for Unbreakable Enterprise kernel (ELSA-2021-9349)
- 159305 Oracle Enterprise Linux Security Update for Unbreakable Enterprise kernel-container (ELSA-2021-9351)
- 159306 Oracle Enterprise Linux Security Update for Unbreakable Enterprise kernel (ELSA-2021-9362)
- 159307 Oracle Enterprise Linux Security Update for Unbreakable Enterprise kernel-container (ELSA-2021-9363)
- 159310 Oracle Enterprise Linux Security Update for kernel (ELSA-2021-2725)
- 179118 Debian Security Update for linux (DLA 2940-1)
- 180016 Debian Security Update for linux (CVE-2021-33033)
- 198398 Ubuntu Security Notification for Linux kernel vulnerabilities (USN-4979-1)
- 198403 Ubuntu Security Notification for Linux kernel vulnerabilities (USN-4984-1)
- 239523 Red Hat Update for kernel-rt (RHSA-2021:2726)
- 239524 Red Hat Update for kernel (RHSA-2021:2725)
- 239879 Red Hat Update for kernel-rt (RHSA-2021:4140)
- 257100 CentOS Security Update for kernel (CESA-2021:2725)
- 352366 Amazon Linux Security Advisory for kernel: ALAS-2021-1503
- 353242 Amazon Linux Security Advisory for kernel : ALAC2012-2022-036
- 353243 Amazon Linux Security Advisory for kmod-mlx5 : ALAC2012-2022-037
- 353244 Amazon Linux Security Advisory for kmod-sfc : ALAC2012-2022-038
- 670488 EulerOS Security Update for kernel (EulerOS-SA-2021-2246)
- 670514 EulerOS Security Update for kernel (EulerOS-SA-2021-2272)
- 670543 EulerOS Security Update for kernel (EulerOS-SA-2021-2301)
- 670578 EulerOS Security Update for kernel (EulerOS-SA-2021-2336)
- 670634 EulerOS Security Update for kernel (EulerOS-SA-2021-2392)
- 671047 EulerOS Security Update for kernel (EulerOS-SA-2021-2588)
- 751336 OpenSUSE Security Update for the Linux Kernel (openSUSE-SU-2021:1460-1)
- 751342 OpenSUSE Security Update for the Linux Kernel (openSUSE-SU-2021:3641-1)
- 751346 OpenSUSE Security Update for the Linux Kernel (openSUSE-SU-2021:3655-1)
- 751349 OpenSUSE Security Update for the Linux Kernel (openSUSE-SU-2021:1477-1)
- 751353 OpenSUSE Security Update for the Linux Kernel (openSUSE-SU-2021:3675-1)
- 751381 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2021:3748-1)
- 751437 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2021:3876-1)
- 751441 OpenSUSE Security Update for the Linux Kernel (openSUSE-SU-2021:3876-1)
- 751451 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2021:3935-1)
- 751473 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2021:3969-1)
- 900096 CBL-Mariner Linux Security Update for kernel 5.10.52.1
- 900304 CBL-Mariner Linux Security Update for kernel 5.10.57.1
- 900319 CBL-Mariner Linux Security Update for kernel 5.10.60.1
- 901876 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (6561-1)
- 902912 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (4203)
- 906180 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (4203-1)
- 940265 AlmaLinux Security Update for kernel (ALSA-2021:4356)