---
cve: "CVE-2021-3609"
severity: "LOW"
cvss: 3.1
epss: "43%"
vendor: "n/a"
kev: false
exploited: false
published: "2022-03-03 19:15:08"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-19T00:38:50+02:00"
---

# CVE-2021-3609

> 3.1 LOW · 🧪 PoC

## Beschreibung

.A flaw was found in the CAN BCM networking protocol in the Linux kernel, where a local attacker can abuse a flaw in the CAN subsystem to corrupt memory, crash the system or escalate privileges. This race condition in net/can/bcm.c in the Linux kernel allows for local privilege escalation to root.

## Patch verfügbar (OSV)

- d5f9023fa61ee8b94f37a93f08e94b136cf1e463 (Commit)

## Referenzen

- <https://bugzilla.redhat.com/show_bug.cgi?id=1971651>
- <https://www.openwall.com/lists/oss-security/2021/06/19/1>
- <https://github.com/nrb547/kernel-exploitation/blob/main/cve-2021-3609/cve-2021-3609.md>
- <https://github.com/torvalds/linux/commit/d5f9023fa61ee8b94f37a93f08e94b136cf1e463>
- <https://security.netapp.com/advisory/ntap-20220419-0004/>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2021-3609) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
