First published: Mon Mar 15 2021(Updated: )
An issue was discovered in the Linux kernel through 5.11.6. fastrpc_internal_invoke in drivers/misc/fastrpc.c does not prevent user applications from sending kernel RPC messages, aka CID-20c40794eb85. This is a related issue to CVE-2019-2308.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Android | ||
Linux Kernel | >=5.1<5.4.106 | |
Linux Kernel | >=5.5<5.10.24 | |
Linux Kernel | >=5.11<5.11.7 | |
Red Hat Fedora | =32 | |
Red Hat Fedora | =33 | |
Red Hat Fedora | =34 | |
NetApp Cloud Backup | ||
NetApp SolidFire Baseboard Management Controller Firmware | ||
debian/linux | 5.10.223-1 5.10.234-1 6.1.129-1 6.1.128-1 6.12.20-1 6.12.21-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-28375 has a moderate severity rating due to its potential exploitation in the Linux kernel.
To fix CVE-2021-28375, update to a patched version of the Linux kernel, such as 5.10.223-1 or later.
CVE-2021-28375 affects Linux kernel versions prior to 5.11.7, as well as earlier versions below 5.4.106 and 5.10.24.
CVE-2021-28375 impacts multiple distributions, including Google Android and Fedoraproject Fedora versions 32, 33, and 34.
Yes, CVE-2021-28375 is related to CVE-2019-2308, highlighting similar issues in the Linux kernel RPC messaging.