CVE-2021-28375

An issue was discovered in the Linux kernel through 5.11.6. fastrpc_internal_invoke in drivers/misc/fastrpc.c does not prevent user applications from sending kernel RPC messages, aka CID-20c40794eb85. This is a related issue to CVE-2019-2308.

Summary:

An issue was discovered in the Linux kernel through 5.11.6. fastrpc_internal_invoke in drivers/misc/fastrpc.c does not prevent user applications from sending kernel RPC messages, aka CID-20c40794eb85. This is a related issue to CVE-2019-2308.

Reference Links(if available):

  • https://lore.kernel.org/stable/[email protected]/
  • https://git.kernel.org/linus/20c40794eb85ea29852d7bc37c55713802a543d6
  • https://lists.fedoraproject.org/archives/list/[email protected]/message/OMRQVOTASD3VZP6GE4JJHE27QU6FHTZ6/
  • https://lists.fedoraproject.org/archives/list/[email protected]/message/TJPVQZPY3DHPV5I3IVNMSMO6D3PKZISX/
  • https://lists.fedoraproject.org/archives/list/[email protected]/message/XAUNYDTGE6MB4NWL2SIHPCODCLET3JZB/
  • CVSS Score (if available)

    v2: / MEDIUMAV:L/AC:L/Au:N/C:C/I:C/A:C

    v3: / HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

    Links to Exploits(if available)