{"id":"CVE-2021-27364","title":"An issue was discovered in the Linux kernel through 5.11.3","summary":"An issue was discovered in the Linux kernel through 5.11.3. drivers/scsi/scsi_transport_iscsi.c is adversely affected by the ability of an unprivileged user to craft Netlink messages.","severity":"high","cvss":7.1,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","cwe":["CWE-125"],"vendor":"netapp","product":"cloud_backup","affected":["cloud_backup","linux_kernel < 4.4.260","linux_kernel >= 4.5, < 4.9.260","linux_kernel >= 4.10, < 4.14.224","linux_kernel >= 4.15, < 4.19.179","linux_kernel >= 4.20, < 5.4.103","linux_kernel >= 5.5, < 5.10.21","linux_kernel >= 5.11, < 5.11.4","debian_linux = 9.0","solidfire_baseboard_management_controller_firmware","tekelec_platform_distribution >= 7.4.0, <= 7.7.1","ubuntu_linux = 14.04","ubuntu_linux = 16.04","ubuntu_linux = 18.04","ubuntu_linux = 20.04"],"patched":["linux_kernel 5.11.4"],"published":"2021-03-07","updated":"2026-07-30","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2021-27364","references":[{"url":"http://packetstormsecurity.com/files/162117/Kernel-Live-Patch-Security-Notice-LSN-0075-1.html","label":"cve@mitre.org"},{"url":"https://blog.grimm-co.com/2021/03/new-old-bugs-in-linux-kernel.html","label":"cve@mitre.org"},{"url":"https://bugzilla.suse.com/show_bug.cgi?id=1182717","label":"cve@mitre.org"},{"url":"https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=688e8128b7a92df982709a4137ea4588d16f24aa","label":"cve@mitre.org"},{"url":"https://lists.debian.org/debian-lts-announce/2021/03/msg00010.html","label":"cve@mitre.org"},{"url":"https://lists.debian.org/debian-lts-announce/2021/03/msg00035.html","label":"cve@mitre.org"},{"url":"https://security.netapp.com/advisory/ntap-20210409-0001/","label":"cve@mitre.org"},{"url":"https://www.openwall.com/lists/oss-security/2021/03/06/1","label":"cve@mitre.org"},{"url":"https://www.oracle.com/security-alerts/cpuoct2021.html","label":"cve@mitre.org"},{"url":"http://packetstormsecurity.com/files/162117/Kernel-Live-Patch-Security-Notice-LSN-0075-1.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://blog.grimm-co.com/2021/03/new-old-bugs-in-linux-kernel.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://bugzilla.suse.com/show_bug.cgi?id=1182717","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=688e8128b7a92df982709a4137ea4588d16f24aa","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2021/03/msg00010.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2021/03/msg00035.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20210409-0001/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.openwall.com/lists/oss-security/2021/03/06/1","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpuoct2021.html","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.00965,"epssPercentile":0.60033,"ingestedAt":"2026-07-30T19:55:34.725Z","slug":"CVE-2021-27364","body":"## Overview\n\nAn issue was discovered in the Linux kernel through 5.11.3. drivers/scsi/scsi_transport_iscsi.c is adversely affected by the ability of an unprivileged user to craft Netlink messages.\n\n## Affected\n\n- `cloud_backup`\n- `linux_kernel < 4.4.260`\n- `linux_kernel >= 4.5, < 4.9.260`\n- `linux_kernel >= 4.10, < 4.14.224`\n- `linux_kernel >= 4.15, < 4.19.179`\n- `linux_kernel >= 4.20, < 5.4.103`\n- `linux_kernel >= 5.5, < 5.10.21`\n- `linux_kernel >= 5.11, < 5.11.4`\n- `debian_linux = 9.0`\n- `solidfire_baseboard_management_controller_firmware`\n- `tekelec_platform_distribution >= 7.4.0, <= 7.7.1`\n- `ubuntu_linux = 14.04`\n- `ubuntu_linux = 16.04`\n- `ubuntu_linux = 18.04`\n- `ubuntu_linux = 20.04`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `linux_kernel 5.11.4`","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":39.1,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}