An issue was discovered in the Linux kernel through 5.11.3. Certain iSCSI data structures do not have appropriate length constraints or checks, and can exceed the PAGE_SIZE value. An unprivileged use…
High CVSS 7.8
Summary
An issue was discovered in the Linux kernel through 5.11.3. Certain iSCSI data structures do not have appropriate length constraints or checks, and can exceed the PAGE_SIZE value. An unprivileged user can send a Netlink message that is associated with iSCSI, and has a length up to the maximum length of a Netlink message.
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
- :
- :
- :
- :
Lint boundary warnings (4)
The following non-blocking warnings were raised during the lint phase of this triage (e.g. reference URLs not yet on the allowlist). They do not affect entry usability and are disclosed for transparency (see DR-002).
-
REF_URL_NOT_ALLOWLISTEDurl not in allowlist: http://packetstormsecurity.com/files/162117/Kernel-Live-Patch-Security-Notice-LSN-0075-1.html -
REF_URL_NOT_ALLOWLISTEDurl not in allowlist: https://blog.grimm-co.com/2021/03/new-old-bugs-in-linux-kernel.html -
REF_URL_NOT_ALLOWLISTEDurl not in allowlist: http://packetstormsecurity.com/files/162117/Kernel-Live-Patch-Security-Notice-LSN-0075-1.html -
REF_URL_NOT_ALLOWLISTEDurl not in allowlist: https://blog.grimm-co.com/2021/03/new-old-bugs-in-linux-kernel.html
Sources
- NVD DATABASE
Original Links
- http://packetstormsecurity.com/files/162117/Kernel-Live-Patch-Security-Notice-LSN-0075-1.html Third Party Advisory
- https://blog.grimm-co.com/2021/03/new-old-bugs-in-linux-kernel.html Exploit
- https://bugzilla.suse.com/show_bug.cgi?id=1182715 Issue Tracking
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=ec98ea7070e94cc25a422ec97d1421e28d97b7ee Mailing List
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=f9dbdf97a5bd92b1a49cee3d591b55b11fd7a6d5 Mailing List
- https://lists.debian.org/debian-lts-announce/2021/03/msg00010.html Mailing List
- https://lists.debian.org/debian-lts-announce/2021/03/msg00035.html Mailing List
- https://security.netapp.com/advisory/ntap-20210409-0001/ Third Party Advisory
- https://www.openwall.com/lists/oss-security/2021/03/06/1 Mailing List
- https://www.oracle.com/security-alerts/cpuoct2021.html Patch
- http://packetstormsecurity.com/files/162117/Kernel-Live-Patch-Security-Notice-LSN-0075-1.html Third Party Advisory
- https://blog.grimm-co.com/2021/03/new-old-bugs-in-linux-kernel.html Exploit
- https://bugzilla.suse.com/show_bug.cgi?id=1182715 Issue Tracking
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=ec98ea7070e94cc25a422ec97d1421e28d97b7ee Mailing List
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=f9dbdf97a5bd92b1a49cee3d591b55b11fd7a6d5 Mailing List
- https://lists.debian.org/debian-lts-announce/2021/03/msg00010.html Mailing List
- https://lists.debian.org/debian-lts-announce/2021/03/msg00035.html Mailing List
- https://security.netapp.com/advisory/ntap-20210409-0001/ Third Party Advisory
- https://www.openwall.com/lists/oss-security/2021/03/06/1 Mailing List
- https://www.oracle.com/security-alerts/cpuoct2021.html Patch
Timeline
- nvd_ingest NVD