Database/Control plane, storage & DevOps
Linux iSCSI: Kernel pointer leak - iscsi_transport handle exposed to unprivileged users via sysfs
CVSS 4.4CVE-2021-27363Control plane, storage & DevOpscurated
Impact
Kernel pointer leak - iscsi_transport handle exposed to unprivileged users via sysfs
Who can reach it
Local
What to do
Data-plane: kernel patch, batch with a reboot window
References
Related entries
- Linux iSCSI: iSCSI netlink structures lack length checksCVE-2021-27365 · Linux iSCSIHigh
- Linux iSCSI: Unprivileged user can craft Netlink messages to scsi_transport_iscsiCVE-2021-27364 · Linux iSCSIHigh
- IBM Spectrum Scale file audit logging retention: A privileged administrator deletes audit records before theirCVE-2021-38882 · IBM Spectrum Scale file audit logging retentionMedium
- Windows Boot Manager: Secure Boot bypass exploited in the wild by the BlackLotus UEFI bootkitCVE-2022-21894 · Windows Boot ManagerMedium
- Redis: Malformed ACL selector triggers a server panicCVE-2024-51741 · RedisMedium
- GitLab EE: Owner or Maintainer can silently disable protected-environment deployment approvalsCVE-2026-86341 · GitLab EE (protected environment deployment approval rules)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.