vulnerability
Oracle Linux: CVE-2021-27365: ELSA-2021-9175: Unbreakable Enterprise kernel-container security update (IMPORTANT) (Multiple Advisories)
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
7 | (AV:L/AC:L/Au:S/C:C/I:C/A:C) | Mar 5, 2021 | Mar 18, 2021 | Jan 23, 2025 |
Severity
7
CVSS
(AV:L/AC:L/Au:S/C:C/I:C/A:C)
Published
Mar 5, 2021
Added
Mar 18, 2021
Modified
Jan 23, 2025
Description
An issue was discovered in the Linux kernel through 5.11.3. Certain iSCSI data structures do not have appropriate length constraints or checks, and can exceed the PAGE_SIZE value. An unprivileged user can send a Netlink message that is associated with iSCSI, and has a length up to the maximum length of a Netlink message.
A flaw was found in the Linux kernel. A heap buffer overflow in the iSCSI subsystem is triggered by setting an iSCSI string attribute to a value larger than one page and then trying to read it. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
A flaw was found in the Linux kernel. A heap buffer overflow in the iSCSI subsystem is triggered by setting an iSCSI string attribute to a value larger than one page and then trying to read it. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Solution(s)
oracle-linux-upgrade-kerneloracle-linux-upgrade-kernel-uek
References
- CVE-2021-27365
- https://attackerkb.com/topics/CVE-2021-27365
- ELSA-ELSA-2021-9175
- ELSA-ELSA-2021-1093
- ELSA-ELSA-2021-1071
- ELSA-ELSA-2021-9164
- ELSA-ELSA-2021-9141
- ELSA-ELSA-2021-9140
- ELSA-ELSA-2021-9116
- ELSA-ELSA-2021-9113
- ELSA-ELSA-2021-9212
- ELSA-ELSA-2021-9114
- ELSA-ELSA-2021-9172
- ELSA-ELSA-2021-9115
- ELSA-ELSA-2021-9112

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.