{"id":"CVE-2021-28972","title":"In drivers/pci/hotplug/rpadlpar_sysfs.c in the Linux kernel through 5.11.8, the RPA PCI Hotplug driver has a user-tolerable buffer overflow when writing a new device name to the driver from userspace, allowing userspace to write data to …","summary":"In drivers/pci/hotplug/rpadlpar_sysfs.c in the Linux kernel through 5.11.8, the RPA PCI Hotplug driver has a user-tolerable buffer overflow when writing a new device name to the driver from userspace, allowing userspace to write data to …","severity":"medium","cvss":6.7,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-120"],"vendor":"netapp","product":"cloud_backup","affected":["linux_kernel < 4.4.263","linux_kernel > 4.5, <= 4.9.263","linux_kernel >= 4.10, < 4.14.227","linux_kernel > 4.15, <= 4.19.183","linux_kernel >= 4.20, < 5.4.108","linux_kernel >= 5.5.0, < 5.10.26","linux_kernel >= 5.11, < 5.11.9","fedora = 32","fedora = 33","fedora = 34","cloud_backup","fas/aff_baseboard_management_controller","solidfire_baseboard_management_controller_firmware"],"patched":["linux_kernel 5.11.9"],"published":"2021-03-22","updated":"2026-10-08","sourceUpdated":"2026-10-08T21:17:34.967","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2021-28972","references":[{"url":"https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=cc7a0bb058b85ea03db87169c60c7cfdd5d34678","label":"cve@mitre.org"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4VCKIOXCOZGXBEZMO5LGGV5MWCHO6FT3/","label":"cve@mitre.org"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PTRNPQTZ4GVS46SZ4OBXY5YDOGVPSTGQ/","label":"cve@mitre.org"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T2S3I4SLRNRUQDOFYUS6IUAZMQNMPNLG/","label":"cve@mitre.org"},{"url":"https://security.netapp.com/advisory/ntap-20210430-0003/","label":"cve@mitre.org"},{"url":"https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=cc7a0bb058b85ea03db87169c60c7cfdd5d34678","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4VCKIOXCOZGXBEZMO5LGGV5MWCHO6FT3/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PTRNPQTZ4GVS46SZ4OBXY5YDOGVPSTGQ/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T2S3I4SLRNRUQDOFYUS6IUAZMQNMPNLG/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20210430-0003/","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.00805,"epssPercentile":0.55435,"ingestedAt":"2026-10-08T22:11:53.730Z","slug":"CVE-2021-28972","body":"## Overview\n\nIn drivers/pci/hotplug/rpadlpar_sysfs.c in the Linux kernel through 5.11.8, the RPA PCI Hotplug driver has a user-tolerable buffer overflow when writing a new device name to the driver from userspace, allowing userspace to write data to the kernel stack frame directly. This occurs because add_slot_store and remove_slot_store mishandle drc_name '\\0' termination, aka CID-cc7a0bb058b8.\n\n## Affected\n\n- `linux_kernel < 4.4.263`\n- `linux_kernel > 4.5, <= 4.9.263`\n- `linux_kernel >= 4.10, < 4.14.227`\n- `linux_kernel > 4.15, <= 4.19.183`\n- `linux_kernel >= 4.20, < 5.4.108`\n- `linux_kernel >= 5.5.0, < 5.10.26`\n- `linux_kernel >= 5.11, < 5.11.9`\n- `fedora = 32`\n- `fedora = 33`\n- `fedora = 34`\n- `cloud_backup`\n- `fas/aff_baseboard_management_controller`\n- `solidfire_baseboard_management_controller_firmware`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `linux_kernel 5.11.9`","depth":"sunlit","depthScore":37,"depthScoreParts":{"impact":36.9,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}