This could be a great time to patch your Linux kernel

An abstract image of padlocks overlaying a digital background.
(Image credit: Shutterstock)

Cybersecurity researchers have helped fix a critical heap-overflow security vulnerability in the Linux kernel that could be exploited either locally or through remote code execution (RCE) to compromise the vulnerable Linux computers.

Discovered by SentinelLabs’ researcher Max Van Amerongen, the vulnerability tracked as CVE-2021-43267 exists in the Transparent Inter Process Communication (TIPC) module of the kernel, specifically in a message type that allows nodes to send cryptographic keys to each other. 

“This vulnerability can be exploited both locally and remotely. While local exploitation is easier due to greater control over the objects allocated in the kernel heap, remote exploitation can be achieved thanks to the structures that TIPC supports,” notes Amerongen.

Since the affected message type is relatively new, the bug only exists in kernel releases between v5.10 and v5.15. 

Caught within an year

The researcher explains that the vulnerable message type, called MSG_CRYPTO, was introduced in September 2020, for exchanging cryptographic keys. 

However, Amerongen discovered that while the message type made various allocations for transferring the keys, it failed to check and validate some of them. 

This oversight could, for instance, enable an attacker to create a packet with a small body size to first allocate heap memory, and then use an arbitrary size in an unchecked attribute to write outside the bounds of this location, explains Amerongen.

Perhaps the one saving grace that has ensured that the vulnerability hasn’t been exploited in the wild is that while the TIPC module comes with all major Linux distros, it’s not enabled by default, which it needs to be for the attackers to exploit.

In any case, a patch has been released that adds appropriate size-verification checks to the process, which has already been added to the mainline Linux 5.15 Long Term Support (LTS) release.

TOPICS
Mayank Sharma

With almost two decades of writing and reporting on Linux, Mayank Sharma would like everyone to think he’s TechRadar Pro’s expert on the topic. Of course, he’s just as interested in other computing topics, particularly cybersecurity, cloud, containers, and coding.

Read more
MediaTek
MediaTek reveals host of security vulnerabilities, so patch now
Digital image of a lock.
Nvidia systems could be facing another worrying security flaw
AMD logo
AMD patches high severity security flaw affecting Zen chips
AMD logo
Security flaw means AMD Zen CPUs can be "jailbroken"
China
Juniper patches security flaws which could have let hackers take over your router
Security
Microsoft reveals more on a potentially major Apple macOS security flaw
Latest in Security
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple routers hit by new critical severity remote command injection vulnerability, with no fix in sight
Code Skull
This dangerous new ransomware is hitting Windows, ARM, ESXi systems
An abstract image of a lock against a digital background, denoting cybersecurity.
Critical security flaw in Next.js could spell big trouble for JavaScript users
Latest in News
Open AI
OpenAI live stream - could we see a major ChatGPT upgrade?
Apple WWDC 2025 announced
Apple just announced WWDC 2025 starts on June 9, and we'll all be watching the opening event
Hornet swings their weapon in mid air
Hollow Knight: Silksong gets new Steam metadata changes, convincing everyone and their mother that the game is finally releasing this year
OpenAI logo
OpenAI just launched a free ChatGPT bible that will help you master the AI chatbot and Sora
NetSuite EVP Evan Goldberg at SuiteConnect London 2025
"It's our job to deliver constant innovation” - NetSuite head on why it wants to be the operating system for your whole business
Monster Hunter Wilds
Monster Hunter Wilds Title Update 1 launches in early April, adding new monsters and some of the best-looking armor sets I need to add to my collection