---
id: CVE-2021-28972
title: >-
  In drivers/pci/hotplug/rpadlpar_sysfs.c in the Linux kernel through 5.11.8,
  the RPA PCI Hotplug driver has a user-tolerable buffer overflow when writing a
  new device name to the driver from userspace, allowing userspace to write data
  to …
summary: >-
  In drivers/pci/hotplug/rpadlpar_sysfs.c in the Linux kernel through 5.11.8,
  the RPA PCI Hotplug driver has a user-tolerable buffer overflow when writing a
  new device name to the driver from userspace, allowing userspace to write data
  to …
severity: medium
cvss: 6.7
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-120
vendor: netapp
product: cloud_backup
affected:
  - linux_kernel < 4.4.263
  - 'linux_kernel > 4.5, <= 4.9.263'
  - 'linux_kernel >= 4.10, < 4.14.227'
  - 'linux_kernel > 4.15, <= 4.19.183'
  - 'linux_kernel >= 4.20, < 5.4.108'
  - 'linux_kernel >= 5.5.0, < 5.10.26'
  - 'linux_kernel >= 5.11, < 5.11.9'
  - fedora = 32
  - fedora = 33
  - fedora = 34
  - cloud_backup
  - fas/aff_baseboard_management_controller
  - solidfire_baseboard_management_controller_firmware
patched:
  - linux_kernel 5.11.9
published: '2021-03-22'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T21:17:34.967'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-28972'
references:
  - url: >-
      https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=cc7a0bb058b85ea03db87169c60c7cfdd5d34678
    label: cve@mitre.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4VCKIOXCOZGXBEZMO5LGGV5MWCHO6FT3/
    label: cve@mitre.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PTRNPQTZ4GVS46SZ4OBXY5YDOGVPSTGQ/
    label: cve@mitre.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T2S3I4SLRNRUQDOFYUS6IUAZMQNMPNLG/
    label: cve@mitre.org
  - url: 'https://security.netapp.com/advisory/ntap-20210430-0003/'
    label: cve@mitre.org
  - url: >-
      https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=cc7a0bb058b85ea03db87169c60c7cfdd5d34678
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4VCKIOXCOZGXBEZMO5LGGV5MWCHO6FT3/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PTRNPQTZ4GVS46SZ4OBXY5YDOGVPSTGQ/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T2S3I4SLRNRUQDOFYUS6IUAZMQNMPNLG/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20210430-0003/'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00805
epssPercentile: 0.55435
ingestedAt: '2026-10-08T22:11:53.730Z'
---

## Overview

In drivers/pci/hotplug/rpadlpar_sysfs.c in the Linux kernel through 5.11.8, the RPA PCI Hotplug driver has a user-tolerable buffer overflow when writing a new device name to the driver from userspace, allowing userspace to write data to the kernel stack frame directly. This occurs because add_slot_store and remove_slot_store mishandle drc_name '\0' termination, aka CID-cc7a0bb058b8.

## Affected

- `linux_kernel < 4.4.263`
- `linux_kernel > 4.5, <= 4.9.263`
- `linux_kernel >= 4.10, < 4.14.227`
- `linux_kernel > 4.15, <= 4.19.183`
- `linux_kernel >= 4.20, < 5.4.108`
- `linux_kernel >= 5.5.0, < 5.10.26`
- `linux_kernel >= 5.11, < 5.11.9`
- `fedora = 32`
- `fedora = 33`
- `fedora = 34`
- `cloud_backup`
- `fas/aff_baseboard_management_controller`
- `solidfire_baseboard_management_controller_firmware`

## Remediation

Upgrade past the affected range:

- `linux_kernel 5.11.9`
