An issue was discovered in the Linux kernel through 5.11.6. fastrpc_internal_invoke in drivers/misc/fastrpc.c does not prevent user applications from sending kernel RPC messages, aka CID-20c40794eb85. This is a related issue to CVE-2019-2308.
References
Link | Resource |
---|---|
https://lore.kernel.org/stable/YD03ew7+6v0XPh6l@kroah.com/ | Mailing List Patch Vendor Advisory |
https://git.kernel.org/linus/20c40794eb85ea29852d7bc37c55713802a543d6 | Mailing List Patch Vendor Advisory |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OMRQVOTASD3VZP6GE4JJHE27QU6FHTZ6/ | Mailing List Third Party Advisory |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TJPVQZPY3DHPV5I3IVNMSMO6D3PKZISX/ | Mailing List Third Party Advisory |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XAUNYDTGE6MB4NWL2SIHPCODCLET3JZB/ | Mailing List Third Party Advisory |
https://security.netapp.com/advisory/ntap-20210401-0003/ | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Information
Published : 2021-03-14 22:15
Updated : 2023-02-24 10:42
NVD link : CVE-2021-28375
Mitre link : CVE-2021-28375
JSON object : View
CWE
CWE-862
Missing Authorization
Products Affected
fedoraproject
- fedora
netapp
- cloud_backup
- solidfire_baseboard_management_controller_firmware
linux
- linux_kernel