An issue was discovered in the Linux kernel through 5.11.3. Certain iSCSI data structures do not have appropriate length constraints or checks, and can exceed the PAGE_SIZE value. An unprivileged user can send a Netlink message that is associated with iSCSI, and has a length up to the maximum length of a Netlink message.
2021-03-07T05:15:13.623
2024-11-21T05:57:50.850
Modified
CVSSv3.1: 7.8 (HIGH)
AV:L/AC:L/Au:N/C:P/I:P/A:P
3.9
6.4
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | linux | linux_kernel | ≤ 5.11.3 | Yes |
| Operating System | debian | debian_linux | 9.0 | Yes |
| Application | oracle | tekelec_platform_distribution | ≤ 7.7.1 | Yes |
| Operating System | netapp | solidfire_baseboard_management_controller_firmware | - | Yes |
| Hardware | netapp | solidfire_baseboard_management_controller | - | No |