← Vulnerability feed

Vulnerability record · CVE-2021-43267 · published 2 November 2021

CVE-2021-43267: Linux kernel TIPC MSG_CRYPTO size validation flaw allows remote code execution

Linux · Linux Kernel

The Linux kernel's TIPC crypto code (net/tipc/crypto.c) fails to properly validate user-supplied sizes for MSG_CRYPTO messages. A remote attacker can send a crafted TIPC packet to trigger heap memory corruption in kernels before 5.14.16. Because TIPC is reachable over the network without credentials, this is a serious pre-authentication kernel flaw.

9.8 CVSS 3.1 Critical EPSS 58% · top 0.9% CWE-1284 · CWE-1284
9.8CVSS 3.1 base score, v2 7.5
58%EPSS exploitation probability, 30 days
NoNot in CISA KEV
9Affected product versions listed by NVD
12References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An issue was discovered in net/tipc/crypto.c in the Linux kernel before 5.14.16. The Transparent Inter-Process Communication (TIPC) functionality allows remote attackers to exploit insufficient validation of user-supplied sizes for the MSG_CRYPTO message type.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityCVSS 9.8 with network reachability, no authentication, no user interaction, and public exploit material make this a top remediation priority.

What it is

The Linux kernel's TIPC crypto code (net/tipc/crypto.c) fails to properly validate user-supplied sizes for MSG_CRYPTO messages. A remote attacker can send a crafted TIPC packet to trigger heap memory corruption in kernels before 5.14.16. Because TIPC is reachable over the network without credentials, this is a serious pre-authentication kernel flaw.

Impact

An attacker can corrupt kernel heap memory, which can lead to remote code execution in kernel context or at minimum a system crash. Full compromise of confidentiality, integrity and availability is possible given the CVSS vector.

Attack surface

Reached over the network via TIPC MSG_CRYPTO messages; the CVSS vector shows AV:N/AC:L/PR:N/UI:N, so no authentication or user interaction is required. The only precondition is that TIPC is enabled and reachable on the target.

Exploitation

Not listed in CISA KEV, but EPSS is 0.57853 (99th percentile) and references carry an Exploit tag, indicating public exploit material exists and exploitation is plausible. No ransomware group is documented as using it.

What to do

  • Upgrade the Linux kernel to 5.14.16 or later, or apply the upstream patch commit fa40d9734a57bcbfa79a280189799f76c88f7bb0.
  • Apply vendor updates for Fedora and NetApp products listed in the advisories.
  • If TIPC is not required, disable or blacklist the tipc kernel module to remove the attack surface.
  • Restrict network access to TIPC ports and segment hosts that must run TIPC.
  • Monitor for and block crafted MSG_CRYPTO traffic at network boundaries where feasible.

Detection

  • Monitor kernel logs for TIPC-related warnings, oopses or crashes that could indicate exploitation attempts.
  • Track for unexpected tipc module loading or TIPC socket activity on hosts that do not normally use it.
  • Use network monitoring to flag anomalous TIPC MSG_CRYPTO traffic, especially malformed or oversized messages.
  • Audit kernel versions across the fleet to identify hosts still running kernels before 5.14.16.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

9 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-43267 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2024-54085AMI MegaRAC SPx BMC authentication bypass via Redfish Host InterfaceAMI's SPx BMC implementation contains an authentication bypass reachable remotely through the Redfish Host Interface, classified as CWE-290 (authenti…KEVEPSS 61%analysed10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed9.8CVE-2025-39682Linux kernel TLS zero-length record handling flaw on rx_listThe Linux kernel TLS receive path mishandles zero-length records that arrive from the rx_list, breaking the assumption that a record type change cann…KEVEPSS 2.9%analysed9.8CVE-2024-4577PHP-CGI on Windows argument injection leads to remote code executionPHP-CGI on Windows can misinterpret characters in the command line passed to Win32 API functions when certain code pages are configured, due to Windo…KEVEPSS 100%analysed9.8CVE-2021-44026Roundcube Webmail SQL injection via search parametersRoundcube Webmail before 1.3.17 and 1.4.x before 1.4.12 is prone to SQL injection through the search or search_params input. The flaw is remotely rea…KEVEPSS 70%analysed9.8CVE-2021-42013Apache HTTP Server path traversal and RCE via incomplete fixThe fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient, leaving a path traversal flaw that lets attackers map URLs to files outside…KEVEPSS 100%analysed9.8CVE-2021-41773Apache HTTP Server 2.4.49 path traversal and RCEA path normalization flaw introduced in Apache HTTP Server 2.4.49 lets attackers map URLs to files outside directories configured by Alias-like direc…KEVEPSS 100%analysed9.8CVE-2021-1870Apple WebKit logic flaw allows remote code executionA logic issue in Apple's WebKit was addressed with improved restrictions, affecting macOS Big Sur, Catalina, Mojave, iOS and iPadOS, plus WebKitGTK a…KEVEPSS 7.7%analysed

Source: NIST National Vulnerability Database (record CVE-2021-43267), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.