In drivers/pci/hotplug/rpadlpar_sysfs.c in the Linux kernel through 5.11.8, the RPA PCI Hotplug driver has a user-tolerable buffer overflow when writing a new device name to the driver from userspace, allowing userspace to write data to the kernel stack frame directly. This occurs because add_slot_store and remove_slot_store mishandle drc_name '\0' termination, aka CID-cc7a0bb058b8.
                
            References
                    Configurations
                    Configuration 1 (hide)
            
            
  | 
    
Configuration 2 (hide)
            
            
  | 
    
Configuration 3 (hide)
            
            
  | 
    
History
                    No history.
Information
                Published : 2021-03-22 17:15
Updated : 2024-11-21 06:00
NVD link : CVE-2021-28972
Mitre link : CVE-2021-28972
CVE.ORG link : CVE-2021-28972
JSON object : View
Products Affected
                netapp
- cloud_backup
 - fas\/aff_baseboard_management_controller
 - solidfire_baseboard_management_controller_firmware
 
fedoraproject
- fedora
 
linux
- linux_kernel
 
CWE
                
                    
                        
                        CWE-120
                        
            Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
