CVE-2021-27365
Last modified
CVE-2021-27365 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. An issue was discovered in the Linux kernel through 5.11.3. Certain iSCSI data structures do not have appropriate length constraints or checks, and can exceed the PAGE_SIZE value. EPSS estimates a 2.08% chance of exploitation in the next 30 days.
Description
An issue was discovered in the Linux kernel through 5.11.3. Certain iSCSI data structures do not have appropriate length constraints or checks, and can exceed the PAGE_SIZE value. An unprivileged user can send a Netlink message that is associated with iSCSI, and has a length up to the maximum length of a Netlink message.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | <= 5.11.3 |
| Debian | Debian Linux | 9.0 |
| Oracle | Tekelec Platform Distribution | >= 7.4.0, <= 7.7.1 |
| Netapp | Solidfire Baseboard Management Controller Firmware | All versions |
References
- http://packetstormsecurity.com/files/162117/Kernel-Live-Patch-Security-Notice-LSN-0075-1.htmlThird Party Advisory, VDB Entry
- https://blog.grimm-co.com/2021/03/new-old-bugs-in-linux-kernel.htmlExploit, Third Party Advisory
- https://bugzilla.suse.com/show_bug.cgi?id=1182715Issue Tracking, Third Party Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=ec98ea7070e94cc25a422ec97d1421e28d97b7eeMailing List, Patch, Vendor Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=f9dbdf97a5bd92b1a49cee3d591b55b11fd7a6d5Mailing List, Patch, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2021/03/msg00010.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/03/msg00035.htmlMailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20210409-0001/Third Party Advisory
- https://www.openwall.com/lists/oss-security/2021/03/06/1Mailing List, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.htmlPatch, Third Party Advisory
- http://packetstormsecurity.com/files/162117/Kernel-Live-Patch-Security-Notice-LSN-0075-1.htmlThird Party Advisory, VDB Entry
- https://blog.grimm-co.com/2021/03/new-old-bugs-in-linux-kernel.htmlExploit, Third Party Advisory
- https://bugzilla.suse.com/show_bug.cgi?id=1182715Issue Tracking, Third Party Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=ec98ea7070e94cc25a422ec97d1421e28d97b7eeMailing List, Patch, Vendor Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=f9dbdf97a5bd92b1a49cee3d591b55b11fd7a6d5Mailing List, Patch, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2021/03/msg00010.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/03/msg00035.htmlMailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20210409-0001/Third Party Advisory
- https://www.openwall.com/lists/oss-security/2021/03/06/1Mailing List, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.htmlPatch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-27365?
How severe is CVE-2021-27365?
How do I fix CVE-2021-27365?
Are you affected by CVE-2021-27365?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
