{"id":"CVE-2021-42252","title":"An issue was discovered in aspeed_lpc_ctrl_mmap in drivers/soc/aspeed/aspeed-lpc-ctrl.c in the Linux kernel before 5.14.6","summary":"An issue was discovered in aspeed_lpc_ctrl_mmap in drivers/soc/aspeed/aspeed-lpc-ctrl.c in the Linux kernel before 5.14.6. Local attackers able to access the Aspeed LPC control interface could overwrite memory in the kernel and potential…","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","vendor":"netapp","product":"cloud_backup","affected":["cloud_backup","linux_kernel >= 4.12, < 4.14.247","linux_kernel >= 4.15, < 4.19.207","linux_kernel >= 4.20, < 5.4.148","linux_kernel >= 5.5, < 5.10.67","linux_kernel >= 5.11, < 5.13.19","linux_kernel >= 5.14, < 5.14.6","h300s_firmware","h500s_firmware","h700s_firmware","h300e_firmware","h500e_firmware","h700e_firmware","h410s_firmware","h410c_firmware","solidfire_baseboard_management_controller_firmware"],"patched":["linux_kernel 5.14.6"],"published":"2021-10-11","updated":"2026-08-05","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2021-42252","references":[{"url":"https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.14.6","label":"cve@mitre.org"},{"url":"https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=b49a0e69a7b1a68c8d3f64097d06dabb770fec96","label":"cve@mitre.org"},{"url":"https://security.netapp.com/advisory/ntap-20211112-0006/","label":"cve@mitre.org"},{"url":"https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.14.6","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=b49a0e69a7b1a68c8d3f64097d06dabb770fec96","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20211112-0006/","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.0037,"epssPercentile":0.30734,"ingestedAt":"2026-08-05T18:50:24.911Z","slug":"CVE-2021-42252","body":"## Overview\n\nAn issue was discovered in aspeed_lpc_ctrl_mmap in drivers/soc/aspeed/aspeed-lpc-ctrl.c in the Linux kernel before 5.14.6. Local attackers able to access the Aspeed LPC control interface could overwrite memory in the kernel and potentially execute privileges, aka CID-b49a0e69a7b1. This occurs because a certain comparison uses values that are not memory sizes.\n\n## Affected\n\n- `cloud_backup`\n- `linux_kernel >= 4.12, < 4.14.247`\n- `linux_kernel >= 4.15, < 4.19.207`\n- `linux_kernel >= 4.20, < 5.4.148`\n- `linux_kernel >= 5.5, < 5.10.67`\n- `linux_kernel >= 5.11, < 5.13.19`\n- `linux_kernel >= 5.14, < 5.14.6`\n- `h300s_firmware`\n- `h500s_firmware`\n- `h700s_firmware`\n- `h300e_firmware`\n- `h500e_firmware`\n- `h700e_firmware`\n- `h410s_firmware`\n- `h410c_firmware`\n- `solidfire_baseboard_management_controller_firmware`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `linux_kernel 5.14.6`","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}