vulnerability

Ubuntu: (Multiple Advisories) (CVE-2021-27363): Linux kernel vulnerabilities

Severity
4
CVSS
(AV:L/AC:L/Au:N/C:P/I:N/A:P)
Published
2021-03-07
Added
2021-03-20
Modified
2023-03-22

Description

An issue was discovered in the Linux kernel through 5.11.3. A kernel pointer leak can be used to determine the address of the iscsi_transport structure. When an iSCSI transport is registered with the iSCSI subsystem, the transport's handle is available to unprivileged users via the sysfs file system, at /sys/class/iscsi_transport/$TRANSPORT_NAME/handle. When read, the show_transport_handle function (in drivers/scsi/scsi_transport_iscsi.c) is called, which leaks the handle. This handle is actually the pointer to an iscsi_transport struct in the kernel module's global variables.

Solution(s)

ubuntu-upgrade-linux-image-3-13-0-185-genericubuntu-upgrade-linux-image-3-13-0-185-generic-lpaeubuntu-upgrade-linux-image-3-13-0-185-lowlatencyubuntu-upgrade-linux-image-4-15-0-1067-oracleubuntu-upgrade-linux-image-4-15-0-1081-raspi2ubuntu-upgrade-linux-image-4-15-0-1087-kvmubuntu-upgrade-linux-image-4-15-0-1095-gcpubuntu-upgrade-linux-image-4-15-0-1096-awsubuntu-upgrade-linux-image-4-15-0-1098-snapdragonubuntu-upgrade-linux-image-4-15-0-1110-azureubuntu-upgrade-linux-image-4-15-0-139-genericubuntu-upgrade-linux-image-4-15-0-139-generic-lpaeubuntu-upgrade-linux-image-4-15-0-139-lowlatencyubuntu-upgrade-linux-image-4-4-0-1088-awsubuntu-upgrade-linux-image-4-4-0-1090-kvmubuntu-upgrade-linux-image-4-4-0-1124-awsubuntu-upgrade-linux-image-4-4-0-1148-raspi2ubuntu-upgrade-linux-image-4-4-0-1152-snapdragonubuntu-upgrade-linux-image-4-4-0-206-genericubuntu-upgrade-linux-image-4-4-0-206-generic-lpaeubuntu-upgrade-linux-image-4-4-0-206-lowlatencyubuntu-upgrade-linux-image-4-4-0-206-powerpc-e500mcubuntu-upgrade-linux-image-4-4-0-206-powerpc-smpubuntu-upgrade-linux-image-4-4-0-206-powerpc64-embubuntu-upgrade-linux-image-4-4-0-206-powerpc64-smpubuntu-upgrade-linux-image-5-10-0-1019-oemubuntu-upgrade-linux-image-5-3-0-1038-raspi2ubuntu-upgrade-linux-image-5-3-0-1041-gkeubuntu-upgrade-linux-image-5-3-0-72-genericubuntu-upgrade-linux-image-5-3-0-72-lowlatencyubuntu-upgrade-linux-image-5-4-0-1012-gkeopubuntu-upgrade-linux-image-5-4-0-1032-raspiubuntu-upgrade-linux-image-5-4-0-1036-kvmubuntu-upgrade-linux-image-5-4-0-1039-gkeubuntu-upgrade-linux-image-5-4-0-1040-gcpubuntu-upgrade-linux-image-5-4-0-1041-awsubuntu-upgrade-linux-image-5-4-0-1041-oracleubuntu-upgrade-linux-image-5-4-0-1043-azureubuntu-upgrade-linux-image-5-4-0-70-genericubuntu-upgrade-linux-image-5-4-0-70-generic-lpaeubuntu-upgrade-linux-image-5-4-0-70-lowlatencyubuntu-upgrade-linux-image-5-6-0-1052-oemubuntu-upgrade-linux-image-5-8-0-1019-raspiubuntu-upgrade-linux-image-5-8-0-1019-raspi-nolpaeubuntu-upgrade-linux-image-5-8-0-1022-kvmubuntu-upgrade-linux-image-5-8-0-1024-oracleubuntu-upgrade-linux-image-5-8-0-1026-azureubuntu-upgrade-linux-image-5-8-0-1026-gcpubuntu-upgrade-linux-image-5-8-0-1027-awsubuntu-upgrade-linux-image-5-8-0-48-genericubuntu-upgrade-linux-image-5-8-0-48-generic-64kubuntu-upgrade-linux-image-5-8-0-48-generic-lpaeubuntu-upgrade-linux-image-5-8-0-48-lowlatencyubuntu-upgrade-linux-image-awsubuntu-upgrade-linux-image-aws-hweubuntu-upgrade-linux-image-aws-lts-18-04ubuntu-upgrade-linux-image-azureubuntu-upgrade-linux-image-azure-edgeubuntu-upgrade-linux-image-azure-lts-18-04ubuntu-upgrade-linux-image-gcpubuntu-upgrade-linux-image-gcp-lts-18-04ubuntu-upgrade-linux-image-genericubuntu-upgrade-linux-image-generic-64kubuntu-upgrade-linux-image-generic-64k-hwe-20-04ubuntu-upgrade-linux-image-generic-hwe-16-04ubuntu-upgrade-linux-image-generic-hwe-18-04ubuntu-upgrade-linux-image-generic-hwe-20-04ubuntu-upgrade-linux-image-generic-lpaeubuntu-upgrade-linux-image-generic-lpae-hwe-16-04ubuntu-upgrade-linux-image-generic-lpae-hwe-18-04ubuntu-upgrade-linux-image-generic-lpae-hwe-20-04ubuntu-upgrade-linux-image-generic-lpae-lts-xenialubuntu-upgrade-linux-image-generic-lts-trustyubuntu-upgrade-linux-image-generic-lts-xenialubuntu-upgrade-linux-image-generic-paeubuntu-upgrade-linux-image-gkeubuntu-upgrade-linux-image-gke-5-3ubuntu-upgrade-linux-image-gke-5-4ubuntu-upgrade-linux-image-gkeopubuntu-upgrade-linux-image-gkeop-5-3ubuntu-upgrade-linux-image-gkeop-5-4ubuntu-upgrade-linux-image-kvmubuntu-upgrade-linux-image-lowlatencyubuntu-upgrade-linux-image-lowlatency-hwe-16-04ubuntu-upgrade-linux-image-lowlatency-hwe-18-04ubuntu-upgrade-linux-image-lowlatency-hwe-20-04ubuntu-upgrade-linux-image-lowlatency-lts-xenialubuntu-upgrade-linux-image-lowlatency-paeubuntu-upgrade-linux-image-oemubuntu-upgrade-linux-image-oem-20-04ubuntu-upgrade-linux-image-oem-20-04bubuntu-upgrade-linux-image-oem-osp1ubuntu-upgrade-linux-image-oracleubuntu-upgrade-linux-image-oracle-lts-18-04ubuntu-upgrade-linux-image-powerpc-e500mcubuntu-upgrade-linux-image-powerpc-smpubuntu-upgrade-linux-image-powerpc64-embubuntu-upgrade-linux-image-powerpc64-smpubuntu-upgrade-linux-image-raspiubuntu-upgrade-linux-image-raspi-hwe-18-04ubuntu-upgrade-linux-image-raspi-nolpaeubuntu-upgrade-linux-image-raspi2ubuntu-upgrade-linux-image-raspi2-hwe-18-04ubuntu-upgrade-linux-image-serverubuntu-upgrade-linux-image-snapdragonubuntu-upgrade-linux-image-snapdragon-hwe-18-04ubuntu-upgrade-linux-image-virtualubuntu-upgrade-linux-image-virtual-hwe-16-04ubuntu-upgrade-linux-image-virtual-hwe-18-04ubuntu-upgrade-linux-image-virtual-hwe-20-04ubuntu-upgrade-linux-image-virtual-lts-xenial
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.