CVE-2021-3609

Updated: 2026-02-27 01:30:22.195101

Description:

.A flaw was found in the CAN BCM networking protocol in the Linux kernel, where a local attacker can abuse a flaw in the CAN subsystem to corrupt memory, crash the system or escalate privileges. This race condition in net/can/bcm.c in the Linux kernel allows for local privilege escalation to root.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x MEDIUM 6.9
CVSS Version 3.x HIGH 7.0

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

CentOS 6 ELS kernel 2.6.32 7.0 HIGH Released CLSA-2022:1650377052 2022-05-05 12:05:16
CentOS 7 ELS kernel 3.10.0 7.0 HIGH Released CLSA-2024:1720468480 2024-07-23 17:32:33
CentOS 8.4 ELS kernel 4.18.0 7.0 HIGH Released 2023-11-15 10:17:55
CentOS 8.5 ELS kernel 4.18.0 7.0 HIGH Already Fixed 2023-11-15 10:17:55
CloudLinux 6 ELS kernel 2.6.32 7.0 HIGH Released CLSA-2023:1687202317 2024-04-09 11:33:50
Oracle Linux 6 ELS kernel 2.6.32 7.0 HIGH Released CLSA-2022:1669850228 2022-11-30 19:56:54
RHEL 7 ELS kernel 3.10.0 7.0 HIGH Released CLSA-2025:1750353839 2025-06-20 00:28:19
Ubuntu 16.04 ELS linux-hwe 4.15.0 7.0 HIGH Released 2023-04-27 14:05:01
Ubuntu 16.04 ELS linux 4.4.0 7.0 HIGH Released CLSA-2022:1667414297 2022-11-02 17:08:16
Ubuntu 18.04 ELS linux 4.15.0 7.0 HIGH Already Fixed 2023-06-02 09:10:20