CVE-2021-27364Out-of-bounds Read in Kernel

CWE-125Out-of-bounds Read12 documents8 sources
Severity
7.1HIGHNVD
EPSS
0.0%
top 89.21%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 7
Latest updateMay 24

Description

An issue was discovered in the Linux kernel through 5.11.3. drivers/scsi/scsi_transport_iscsi.c is adversely affected by the ability of an unprivileged user to craft Netlink messages.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:HExploitability: 1.8 | Impact: 5.2

Affected Packages3 packages

Debianlinux/linux_kernel< 5.10.24-1+3
NVDlinux/linux_kernel5.11.3

Also affects: Debian Linux 9.0, Ubuntu Linux 14.04, 16.04, 18.04, 20.04

Patches

🔴Vulnerability Details

4
GHSA
GHSA-qh7p-rxx9-vwx2: An issue was discovered in the Linux kernel through 52022-05-24
OSV
linux, linux-lts-xenial vulnerabilities2021-03-25
OSV
CVE-2021-27364: An issue was discovered in the Linux kernel through 52021-03-07
CVEList
CVE-2021-27364: An issue was discovered in the Linux kernel through 52021-03-07

📋Vendor Advisories

7
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities2021-04-06
Ubuntu
Linux kernel vulnerabilities2021-03-29
Ubuntu
Linux kernel vulnerabilities2021-03-25
Ubuntu
Linux kernel vulnerabilities2021-03-23
Microsoft
An issue was discovered in the Linux kernel through 5.11.3. drivers/scsi/scsi_transport_iscsi.c is adversely affected by the ability of an unprivileged user to craft Netlink messages.2021-03-09