First published: Mon Mar 22 2021(Updated: )
A flaw was found in the Linux kernel. On some Haswell CPUs, userspace applications (such as perf-fuzzer) can cause a system crash because the PEBS status in a PEBS record is mishandled.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/kernel-rt | <0:4.18.0-348.rt7.130.el8 | 0:4.18.0-348.rt7.130.el8 |
redhat/kernel | <0:4.18.0-348.el8 | 0:4.18.0-348.el8 |
Linux Kernel | <=5.11.8 | |
Red Hat Fedora | =32 | |
Red Hat Fedora | =33 | |
Red Hat Fedora | =34 | |
Debian Linux | =9.0 | |
NetApp Cloud Backup | ||
NetApp SolidFire Baseboard Management Controller Firmware | ||
All of | ||
NetApp A250 Firmware | ||
NetApp A250 Firmware | ||
All of | ||
NetApp FAS 500F Firmware | ||
NetApp AFF 500F Firmware | ||
NetApp A250 Firmware | ||
NetApp A250 Firmware | ||
NetApp FAS 500F Firmware | ||
NetApp AFF 500F Firmware | ||
debian/linux | 5.10.223-1 5.10.234-1 6.1.129-1 6.1.128-1 6.12.20-1 6.12.21-1 |
Mitigation for this issue is either not available or the currently available options does not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-28971 is classified as a high severity vulnerability due to its potential to cause system crashes on vulnerable systems.
To fix CVE-2021-28971, update your Linux kernel to at least version 0:4.18.0-348.rt7.130.el8 or a later patched version.
CVE-2021-28971 affects specific Linux kernel versions running on Haswell CPUs.
Yes, if exploited, CVE-2021-28971 can potentially lead to data loss due to system crashes.
As of now, there are no public exploits specifically targeting CVE-2021-28971 reported.