← Back

CVE-2021-28972

nvd nist
Published: Mar 22, 2021Modified: Jun 17, 2026

JSON object

Loading...
6.7
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 0.8 / Impact: 5.9
Source: NVD

Description

In drivers/pci/hotplug/rpadlpar_sysfs.c in the Linux kernel through 5.11.8, the RPA PCI Hotplug driver has a user-tolerable buffer overflow when writing a new device name to the driver from userspace, allowing userspace to write data to the kernel stack frame directly. This occurs because add_slot_store and remove_slot_store mishandle drc_name '\0' termination, aka CID-cc7a0bb058b8.

Affected (13)

1 product
Linux Kernel
1 product
Fedora
3 products
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
Linux
Before 4.4.263
After 4.15 to 4.19.183
After 4.5 to 4.9.263
From 4.10 to 4.14.227
From 4.20 to 5.4.108
From 5.11 to 5.11.9
From 5.5.0 to 5.10.26
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 32
Version 33
Version 34
Configuration C
3 vulnerable

References (10)

Source: cve@mitre.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.