Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Mon, 10 May 2021 06:24:43 +0200
From: Salvatore Bonaccorso <>
Cc: Nadav Markus <>,
	Or Cohen <>
Subject: Re: CVE-2021-23133: Linux kernel: race condition in
 sctp sockets


On Sun, Apr 18, 2021 at 11:41:06AM +0300, Or Cohen wrote:
> Hello,
> This is an announcement about CVE-2021-23133 which is a race-condition
> I found in Linux kernel sctp sockets (net/sctp/socket.c). It can lead to kernel
> privilege escalation from the context of a network service or from
> an unprivileged process if certain conditions are met.
> The bug was fixed on April 13, 2021:

It looks that additionally
refer to CVE-2021-23133.

Are both commits necessary?


Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.