First published: Mon Mar 22 2021(Updated: )
A flaw was found in the Linux kernel. On some Haswell CPUs, userspace applications (such as perf-fuzzer) can cause a system crash because the PEBS status in a PEBS record is mishandled.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/kernel-rt | <0:4.18.0-348.rt7.130.el8 | 0:4.18.0-348.rt7.130.el8 |
redhat/kernel | <0:4.18.0-348.el8 | 0:4.18.0-348.el8 |
debian/linux | 5.10.223-1 5.10.226-1 6.1.123-1 6.1.128-1 6.12.12-1 6.12.15-1 | |
Linux Kernel | <=5.11.8 | |
Fedora | =32 | |
Fedora | =33 | |
Fedora | =34 | |
Debian | =9.0 | |
netapp cloud backup | ||
netapp solidfire baseboard management controller firmware | ||
All of | ||
netapp aff a250 firmware | ||
netapp aff a250 | ||
All of | ||
netapp aff 500f firmware | ||
netapp aff 500f | ||
netapp aff a250 firmware | ||
netapp aff a250 | ||
netapp aff 500f firmware | ||
netapp aff 500f |
Mitigation for this issue is either not available or the currently available options does not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-28971 is classified as a high severity vulnerability due to its potential to cause system crashes on vulnerable systems.
To fix CVE-2021-28971, update your Linux kernel to at least version 0:4.18.0-348.rt7.130.el8 or a later patched version.
CVE-2021-28971 affects specific Linux kernel versions running on Haswell CPUs.
Yes, if exploited, CVE-2021-28971 can potentially lead to data loss due to system crashes.
As of now, there are no public exploits specifically targeting CVE-2021-28971 reported.