Description
An issue was discovered in the Linux kernel through 5.11.3. A kernel pointer leak can be used to determine the address of the iscsi_transport structure. When an iSCSI transport is registered with the iSCSI subsystem, the transport's handle is available to unprivileged users via the sysfs file system, at /sys/class/iscsi_transport/$TRANSPORT_NAME/handle. When read, the show_transport_handle function (in drivers/scsi/scsi_transport_iscsi.c) is called, which leaks the handle. This handle is actually the pointer to an iscsi_transport struct in the kernel module's global variables.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2586-1 | linux security update |
Debian DLA |
DLA-2610-1 | linux-4.19 security update |
EUVD |
EUVD-2021-14122 | An issue was discovered in the Linux kernel through 5.11.3. A kernel pointer leak can be used to determine the address of the iscsi_transport structure. When an iSCSI transport is registered with the iSCSI subsystem, the transport's handle is available to unprivileged users via the sysfs file system, at /sys/class/iscsi_transport/$TRANSPORT_NAME/handle. When read, the show_transport_handle function (in drivers/scsi/scsi_transport_iscsi.c) is called, which leaks the handle. This handle is actually the pointer to an iscsi_transport struct in the kernel module's global variables. |
Ubuntu USN |
USN-4883-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-4887-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-4889-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-4901-1 | Linux kernel (Trusty HWE) vulnerabilities |
References
History
No history.
Subscriptions
Debian
Subscribe
Debian Linux
Subscribe
Linux
Subscribe
Linux Kernel
Subscribe
Netapp
Subscribe
Cloud Backup
Subscribe
Solidfire Baseboard Management Controller Firmware
Subscribe
Redhat
Subscribe
Enterprise Linux
Subscribe
Rhel Aus
Subscribe
Rhel E4s
Subscribe
Rhel Eus
Subscribe
Rhel Extras Rt
Subscribe
Rhel Tus
Subscribe
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-03T20:48:16.475Z
Reserved: 2021-02-17T00:00:00.000Z
Link: CVE-2021-27363
No data.
Status : Modified
Published: 2021-03-07T04:15:13.330
Modified: 2024-11-21T05:57:50.513
Link: CVE-2021-27363
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD
Ubuntu USN