CVE-2021-42252: High severity Linux Linux kernel vulnerability
An issue was discovered in aspeedlpcctrlmmap in drivers/soc/aspeed/aspeed-lpc-ctrl.c in the Linux kernel before 5.14.6. Local attackers able to access the Aspeed LPC control interface could overwrite memory in the kernel and potentially execute privileges, aka CID-b49a0e69a7b1. This occurs because a certain comparison uses values that are not memory sizes.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1Fixed in 6.12.27-1 - Upgrade
Upgrade
Linux kernelto a version that resolves this vulnerability.Fixed in 5.14.6
Event History
Frequently Asked Questions
What is the severity of CVE-2021-42252?
CVE-2021-42252 has a high severity due to its potential to allow local attackers to execute arbitrary code in the kernel.
How do I fix CVE-2021-42252?
To resolve CVE-2021-42252, update the Linux kernel to version 5.14.6 or later.
Who is affected by CVE-2021-42252?
CVE-2021-42252 affects local users with access to the Aspeed LPC control interface in vulnerable Linux kernels.
What allows exploitation of CVE-2021-42252?
Exploitation of CVE-2021-42252 is possible because local attackers can overwrite kernel memory through the Aspeed LPC control interface.
What Linux kernel versions are vulnerable to CVE-2021-42252?
Linux kernel versions prior to 5.14.6 are vulnerable to CVE-2021-42252.