Database/Control plane, storage & DevOps
Linux iSCSI: iSCSI netlink structures lack length checks
CVSS 7.8CVE-2021-27365Control plane, storage & DevOpscurated
Impact
iSCSI netlink structures lack length checks -> heap overflow, unprivileged local root
Who can reach it
Local
What to do
Data-plane: kernel patch + reboot on every node using iSCSI LUNs
References
Related entries
- Linux iSCSI: Unprivileged user can craft Netlink messages to scsi_transport_iscsiCVE-2021-27364 · Linux iSCSIHigh
- Linux iSCSI: Kernel pointer leak - iscsi_transport handle exposed to unprivileged users via sysfsCVE-2021-27363 · Linux iSCSIMedium
- IBM Spectrum Scale core component (format string handling): A user with a shell on any node that runs Storage ScaleCVE-2021-29740 · IBM Spectrum Scale core component (format string handling)High
- Intel Virtual RAID on CPU (VROC) software before 7.7.6.1003, with follow-on issues through 8.6.0.1191: Use-after-freeCVE-2022-29919 · Intel Virtual RAID on CPU (VROC) software before 7.7.6.1003, with follow-on issues through 8.6.0.1191High
- Ceph: ceph-crash.service local privilege escalation to root plus privileged crash-dump disclosureCVE-2022-3650 · CephHigh
- Ampere Altra before 1.08g and Altra Max before 2.05a - return address prediction: An attacker can controlCVE-2022-37459 · Ampere Altra before 1.08g and Altra Max before 2.05a - return address predictionHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.