Vulnerability record · CVE-2021-43267 · published 2 November 2021
CVE-2021-43267: Linux kernel TIPC MSG_CRYPTO size validation flaw allows remote code execution
Linux · Linux Kernel
The Linux kernel's TIPC crypto code (net/tipc/crypto.c) fails to properly validate user-supplied sizes for MSG_CRYPTO messages. A remote attacker can send a crafted TIPC packet to trigger heap memory corruption in kernels before 5.14.16. Because TIPC is reachable over the network without credentials, this is a serious pre-authentication kernel flaw.
Description
An issue was discovered in net/tipc/crypto.c in the Linux kernel before 5.14.16. The Transparent Inter-Process Communication (TIPC) functionality allows remote attackers to exploit insufficient validation of user-supplied sizes for the MSG_CRYPTO message type.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication, no user interaction, and public exploit material make this a top remediation priority.
What it is
The Linux kernel's TIPC crypto code (net/tipc/crypto.c) fails to properly validate user-supplied sizes for MSG_CRYPTO messages. A remote attacker can send a crafted TIPC packet to trigger heap memory corruption in kernels before 5.14.16. Because TIPC is reachable over the network without credentials, this is a serious pre-authentication kernel flaw.
Impact
An attacker can corrupt kernel heap memory, which can lead to remote code execution in kernel context or at minimum a system crash. Full compromise of confidentiality, integrity and availability is possible given the CVSS vector.
Attack surface
Reached over the network via TIPC MSG_CRYPTO messages; the CVSS vector shows AV:N/AC:L/PR:N/UI:N, so no authentication or user interaction is required. The only precondition is that TIPC is enabled and reachable on the target.
Exploitation
Not listed in CISA KEV, but EPSS is 0.57853 (99th percentile) and references carry an Exploit tag, indicating public exploit material exists and exploitation is plausible. No ransomware group is documented as using it.
What to do
- Upgrade the Linux kernel to 5.14.16 or later, or apply the upstream patch commit fa40d9734a57bcbfa79a280189799f76c88f7bb0.
- Apply vendor updates for Fedora and NetApp products listed in the advisories.
- If TIPC is not required, disable or blacklist the tipc kernel module to remove the attack surface.
- Restrict network access to TIPC ports and segment hosts that must run TIPC.
- Monitor for and block crafted MSG_CRYPTO traffic at network boundaries where feasible.
Detection
- Monitor kernel logs for TIPC-related warnings, oopses or crashes that could indicate exploitation attempts.
- Track for unexpected tipc module loading or TIPC socket activity on hosts that do not normally use it.
- Use network monitoring to flag anomalous TIPC MSG_CRYPTO traffic, especially malformed or oversized messages.
- Audit kernel versions across the fleet to identify hosts still running kernels before 5.14.16.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
9 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2021-43267 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-43267), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.