CVE-2021-43267

CRITICALNVD 9.89.8
EchelonGraph scoreMEDIUM confidence

Score 9.8 from GitHub Security Advisory (severity: CRITICAL) published 2022-05-24. NVD baseline CVSS 9.8; sources differ by 0.0.

Triggered by: GitHub Security Advisory CVSS
Sources: epss, ghsa, nvd
Elevated
9.8
EchelonGraph verdictPatch this weekExploitation is likely or a public exploit exists.
  • High exploitation likelihood — EPSS 58%
CISA-KEV: Not listedEPSS: 58%CVSS: 9.8Exploit: NoneExposed: 0

A fix is available — apply it.

An issue was discovered in net/tipc/crypto.c in the Linux kernel before 5.14.16. The Transparent Inter-Process Communication (TIPC) functionality allows remote attackers to exploit insufficient validation of user-supplied sizes for the MSG_CRYPTO message type.

CVSS v3
9.8
EG Score
9.8(medium)
EPSS
99.0%
KEV
Not listed

Published

November 2, 2021

Last Modified

November 21, 2024

Advisory Details (6)

Auto-updated May 26, 2026
⚠️ Active exploitation confirmed. Upstream fix merged — awaiting tagged release. Sources: github_commit.
generic

[SECURITY] Fedora 34 Update: kernel-5.14.16-201.fc34 - package-announce - Fedora mailing-lists

https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CVWL7HZV5T5OEKJPO2D67RMFMKBBXGGB/
github_commit

commit fa40d9734a57 (torvalds/linux)

Fix landed in torvalds/linux commit fa40d9734a57 — awaiting tagged release

https://github.com/torvalds/linux/commit/fa40d9734a57bcbfa79a280189799f76c88f7bb0
generic

oss-security - CVE-2022-0435: Remote Stack Overflow in Linux Kernel TIPC Module since 4.8 (net/tipc)

http://www.openwall.com/lists/oss-security/2022/02/10/1
generic

[SECURITY] Fedora 35 Update: kernel-5.14.16-301.fc35 - package-announce - Fedora mailing-lists

https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RDDEW4APTYKJK365HC2JZIVXYUV7ZRN7/

Patch Availability(10)

Patches are aggregated from vendor advisories (Red Hat, Microsoft, Cisco, GitHub) and package ecosystems (OSV, GHSA). Multiple rows for the same upstream release have been deduplicated.

Weakness Classification(2)

MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.

Additional Vendor Advisories

(8)

Publicly available exploits

(1 reference)

Working exploit code is in the public domain (1 GitHub PoC). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.

  • GitHub PoCzzhacked/CVE-2021-43267
    First seen Nov 26, 2021

    Local PoC exploit for CVE-2021-43267 (Linux TIPC)

    Open source ↗

Frequently asked(5)

What is CVE-2021-43267?
CVE-2021-43267 is a critical vulnerability published on November 2, 2021. An issue was discovered in net/tipc/crypto.c in the Linux kernel before 5.14.16. The Transparent Inter-Process Communication (TIPC) functionality allows remote attackers to exploit insufficient validation of user-supplied sizes for the MSG_CRYPTO message type.
When was CVE-2021-43267 disclosed?
CVE-2021-43267 was first published in the National Vulnerability Database on November 2, 2021, with the most recent update on November 21, 2024. EchelonGraph re-ingests CVE updates from NVD on a 2-hour cycle, so this page reflects the latest published state.
Is CVE-2021-43267 actively exploited?
CVE-2021-43267 is not currently on CISA's Known Exploited Vulnerabilities catalog. FIRST EPSS estimates a 99.0% percentile likelihood of exploitation in the next 30 days — higher percentiles indicate greater predicted risk.
What is the CVSS score of CVE-2021-43267?
CVE-2021-43267 has a CVSS v3 base score of 9.8 (NVD).
How do I remediate CVE-2021-43267?
Patch to the fixed version published by the affected vendor. Where vendor advisories exist for CVE-2021-43267, EchelonGraph cross-links them in the Vendor Advisories panel below — those typically contain the canonical remediation steps, fixed version numbers, and any vendor-specific mitigations.

Dependency Blast Radius

Explore the affected products and dependency analysis for CVE-2021-43267

Explore →

Is Your Infrastructure Affected by CVE-2021-43267?

EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.