CVE-2021-28972Medium· 6.7▾ SunlitIn drivers/pci/hotplug/rpadlpar_sysfs.c in the Linux kernel through 5.11.8, the RPA PCI Hotplug driver has a user-tolerable buffer overflow when writing a new device name to the driver from userspace, allowing userspace to write data to …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 36.9 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.8%
In drivers/pci/hotplug/rpadlpar_sysfs.c in the Linux kernel through 5.11.8, the RPA PCI Hotplug driver has a user-tolerable buffer overflow when writing a new device name to the driver from userspace, allowing userspace to write data to the kernel stack frame directly. This occurs because add_slot_store and remove_slot_store mishandle drc_name '\0' termination, aka CID-cc7a0bb058b8.
linux_kernel < 4.4.263linux_kernel > 4.5, <= 4.9.263linux_kernel >= 4.10, < 4.14.227linux_kernel > 4.15, <= 4.19.183linux_kernel >= 4.20, < 5.4.108linux_kernel >= 5.5.0, < 5.10.26linux_kernel >= 5.11, < 5.11.9fedora = 32fedora = 33fedora = 34cloud_backupfas/aff_baseboard_management_controllersolidfire_baseboard_management_controller_firmwareUpgrade past the affected range:
linux_kernel 5.11.9Connected by shared product, vendor, weakness, or advisory.
CVE-2021-43975Medium· 6.7In the Linux kernel through 5.15.2, hw_atl_utils_fw_rpc_wait in drivers/net/ethernet/aquantia/atlantic/hw_atl/hw_atl_utils.c allows an attacker (who can introduce a crafted device) to trigger an out-of-bounds write via a crafted length v…
CVE-2020-24486Medium· 5.5Improper input validation in the firmware for some Intel(R) Processors may allow an authenticated user to potentially enable denial of service via local access.
CVE-2020-28097Medium· 5.9The vgacon subsystem in the Linux kernel before 5.8.10 mishandles software scrollback
CVE-2020-8670Medium· 6.4Race condition in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
CVE-2020-8700Medium· 6.7Improper input validation in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
CVE-2020-12357Medium· 6.7Improper initialization in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.