Vulnerability in the Linux kernel affecting the CAN BCM network protocol
A vulnerability (CVE-2021-3609) has been identified in the Linux kernel, allowing a local user to elevate their privileges in the system. The issue is caused by a race condition in the implementation of the CAN BCM protocol and is present in Linux kernel releases from 2.6.25 to 5.13-rc6. The problem remains unpatched in distributions (RHEL, Fedora, Debian, Ubuntu, SUSE, Arch). The researcher who discovered the vulnerability was able to craft an exploit to gain root rights […]
