CVE-2021-27364
גבוהה 7.1
תיאור (מקור, אנגלית)
An issue was discovered in the Linux kernel through 5.11.3. drivers/scsi/scsi_transport_iscsi.c is adversely affected by the ability of an unprivileged user to craft Netlink messages.
מדדים
- CVSS 3.1
-
7.1 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H - CWE
- CWE-125
מוצרים מושפעים
netapp: cloud backup; linux: linux kernel; debian: debian linux; netapp: solidfire baseboard management controller firmware; netapp: solidfire baseboard management controller; oracle: tekelec platform distribution; canonical: ubuntu linux
קישורים
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=… Mailing ListPatchVendor Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=… Mailing ListPatchVendor Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.html PatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.html PatchThird Party Advisory
- https://blog.grimm-co.com/2021/03/new-old-bugs-in-linux-kernel.html ExploitThird Party Advisory
- https://blog.grimm-co.com/2021/03/new-old-bugs-in-linux-kernel.html ExploitThird Party Advisory
- http://packetstormsecurity.com/files/162117/Kernel-Live-Patch-Security-Notice-… Third Party AdvisoryVDB Entry
- https://bugzilla.suse.com/show_bug.cgi?id=1182717 Issue TrackingThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/03/msg00010.html Mailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/03/msg00035.html Mailing ListThird Party Advisory