A vulnerability was found in Linux Kernel, where race conditions caused by wrong locking in net/vmw_vsock/af_vsock.c Upstream patch: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=c518adafa39f37858697ac9309c6cf1805581446
Created kernel tracking bugs for this issue: Affects: fedora-all [bug 1925595]
External References: https://www.openwall.com/lists/oss-security/2021/02/04/5
Acknowledgments: Name: Alexander Popov
This is fixed for Fedora with the 5.10.13 stable kernel update.
Statement: This issue does affect the Red Hat Enterprise Linux 8 kernel versions kernel-4.18.0-240 onwards, starting with Red Hat Enterprise Linux 8.3 GA, which introduced VSOCK multi-transport support. Prior Red Hat Enterprise Linux kernel versions are not affected by this issue.
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2021:1081 https://access.redhat.com/errata/RHSA-2021:1081
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2021:1093 https://access.redhat.com/errata/RHSA-2021:1093
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2021-26708