CVE-2021-27365Out-of-bounds Write in Kernel

Severity
7.8HIGHNVD
OSV4.4
EPSS
0.5%
top 34.12%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 7
Latest updateMay 24

Description

An issue was discovered in the Linux kernel through 5.11.3. Certain iSCSI data structures do not have appropriate length constraints or checks, and can exceed the PAGE_SIZE value. An unprivileged user can send a Netlink message that is associated with iSCSI, and has a length up to the maximum length of a Netlink message.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages4 packages

Debianlinux/linux_kernel< 5.10.24-1+3
Ubuntulinux/linux_kernel< 4.4.0-206.238+2
NVDlinux/linux_kernel5.11.3

Also affects: Debian Linux 9.0

Patches

🔴Vulnerability Details

5
GHSA
GHSA-qwp9-8pwv-6hg4: An issue was discovered in the Linux kernel through 52022-05-24
OSV
linux, linux-aws, linux-aws-hwe, linux-azure, linux-azure-4.15, linux-gcp, linux-gcp-4.15, linux-hwe, linux-kvm, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities2021-03-29
OSV
linux, linux-lts-xenial vulnerabilities2021-03-25
CVEList
CVE-2021-27365: An issue was discovered in the Linux kernel through 52021-03-07
OSV
CVE-2021-27365: An issue was discovered in the Linux kernel through 52021-03-07

📋Vendor Advisories

7
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities2021-04-06
Ubuntu
Linux kernel vulnerabilities2021-03-29
Ubuntu
Linux kernel vulnerabilities2021-03-25
Ubuntu
Linux kernel vulnerabilities2021-03-23
Microsoft
An issue was discovered in the Linux kernel through 5.11.3. Certain iSCSI data structures do not have appropriate length constraints or checks and can exceed the PAGE_SIZE value. An unprivileged user 2021-03-09
CVE-2021-27365 — Out-of-bounds Write in Linux Kernel | cvebase