---
id: CVE-2021-27365
title: An issue was discovered in the Linux kernel through 5.11.3
summary: >-
  An issue was discovered in the Linux kernel through 5.11.3. Certain iSCSI data
  structures do not have appropriate length constraints or checks, and can
  exceed the PAGE_SIZE value. An unprivileged user can send a Netlink message
  that is a…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-787
vendor: netapp
product: cloud_backup
affected:
  - cloud_backup
  - linux_kernel < 4.4.260
  - 'linux_kernel >= 4.5, < 4.9.260'
  - 'linux_kernel >= 4.10, < 4.14.224'
  - 'linux_kernel >= 4.15, < 4.19.179'
  - 'linux_kernel >= 4.20, < 5.4.103'
  - 'linux_kernel >= 5.5, < 5.10.21'
  - 'linux_kernel >= 5.11, < 5.11.4'
  - debian_linux = 9.0
  - 'tekelec_platform_distribution >= 7.4.0, <= 7.7.1'
  - solidfire_baseboard_management_controller_firmware
patched:
  - linux_kernel 5.11.4
published: '2021-03-07'
updated: '2026-07-30'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-27365'
references:
  - url: >-
      http://packetstormsecurity.com/files/162117/Kernel-Live-Patch-Security-Notice-LSN-0075-1.html
    label: cve@mitre.org
  - url: 'https://blog.grimm-co.com/2021/03/new-old-bugs-in-linux-kernel.html'
    label: cve@mitre.org
  - url: 'https://bugzilla.suse.com/show_bug.cgi?id=1182715'
    label: cve@mitre.org
  - url: >-
      https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=ec98ea7070e94cc25a422ec97d1421e28d97b7ee
    label: cve@mitre.org
  - url: >-
      https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=f9dbdf97a5bd92b1a49cee3d591b55b11fd7a6d5
    label: cve@mitre.org
  - url: 'https://lists.debian.org/debian-lts-announce/2021/03/msg00010.html'
    label: cve@mitre.org
  - url: 'https://lists.debian.org/debian-lts-announce/2021/03/msg00035.html'
    label: cve@mitre.org
  - url: 'https://security.netapp.com/advisory/ntap-20210409-0001/'
    label: cve@mitre.org
  - url: 'https://www.openwall.com/lists/oss-security/2021/03/06/1'
    label: cve@mitre.org
  - url: 'https://www.oracle.com/security-alerts/cpuoct2021.html'
    label: cve@mitre.org
  - url: >-
      http://packetstormsecurity.com/files/162117/Kernel-Live-Patch-Security-Notice-LSN-0075-1.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://blog.grimm-co.com/2021/03/new-old-bugs-in-linux-kernel.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://bugzilla.suse.com/show_bug.cgi?id=1182715'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=ec98ea7070e94cc25a422ec97d1421e28d97b7ee
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=f9dbdf97a5bd92b1a49cee3d591b55b11fd7a6d5
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2021/03/msg00010.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2021/03/msg00035.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20210409-0001/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.openwall.com/lists/oss-security/2021/03/06/1'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpuoct2021.html'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - exploit-available
epss: 0.02097
epssPercentile: 0.80886
ingestedAt: '2026-07-30T19:55:34.802Z'
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/WhatsWrongAndWhy/CVE-2021-27365'
  checkedAt: '2026-09-26T09:05:26.433Z'
exploitAvailable: true
---

## Overview

An issue was discovered in the Linux kernel through 5.11.3. Certain iSCSI data structures do not have appropriate length constraints or checks, and can exceed the PAGE_SIZE value. An unprivileged user can send a Netlink message that is associated with iSCSI, and has a length up to the maximum length of a Netlink message.

## Affected

- `cloud_backup`
- `linux_kernel < 4.4.260`
- `linux_kernel >= 4.5, < 4.9.260`
- `linux_kernel >= 4.10, < 4.14.224`
- `linux_kernel >= 4.15, < 4.19.179`
- `linux_kernel >= 4.20, < 5.4.103`
- `linux_kernel >= 5.5, < 5.10.21`
- `linux_kernel >= 5.11, < 5.11.4`
- `debian_linux = 9.0`
- `tekelec_platform_distribution >= 7.4.0, <= 7.7.1`
- `solidfire_baseboard_management_controller_firmware`

## Remediation

Upgrade past the affected range:

- `linux_kernel 5.11.4`
