> Source: [sk176864](https://support.checkpoint.com/results/sk/sk176864)

# sk176864 - Check Point response to CVE-2021-43267

| Property | Value |
|----------|-------|
| Solution ID | sk176864 |
| Date Created | 2021-12-11 |
| Last Modified | 2021-12-15 |
| Technical Level | General |
| OS | Gaia |

## Symptoms

- A flaw was discovered in the cryptographic receive code in the Linux kernel's implementation of transparent inter-process communication. An attacker with the ability to send TIPC messages to the target can cause memory corruption and escalate privileges on the target system.

## Cause

This issue affects Red Hat Enterprise Linux 8, starting with the kernel shipped with Red Hat Enterprise Linux 8.4 GA (kernel-4.18.0-305.el8).  
Red Hat recommends using transport level to separate and/or secure (by both encrypting and authenticating via, for example, IPSec/MACSec) the communication between nodes. This limits the exposure of this issue to semi-trusted nodes.

## Solution

Check Point Gaia is not vulnerable to [CVE-2021-43267](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-43267) as the vulnerable functionality is not included.  

Investigated findings for CVE-2021-43267 are as follows:  

<https://access.redhat.com/security/cve/CVE-2021-43267> states that this issue affects Red Hat Enterprise Linux 8, starting with the kernel that shipped with Red Hat Enterprise Linux 8.4 GA (kernel-4.18.0-305.el8). Previous Red Hat Enterprise Linux 8 kernel versions are not affected because they do not include the vulnerable functionality.  

In Summary,  

* Check Point hardened OS with kernel 2.16 (R77, R80, R80.10, R80.20) **are not vulnerable**
* Check Point hardened OS with kernel 3.10 (R80.20, R80.30, R80.40, R81, R81.10 and higher) **are not vulnerable**

<br />

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
