Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:29932
HistoryApr 07, 2021 - 9:16 a.m.

Privilege Escalation

2021-04-0709:16:26
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
25

0.001 Low

EPSS

Percentile

39.3%

kernel-rt is vulnerable to privilege escalation. The vulnerability exists due to certain iSCSI data structures do not have appropriate length constraints or checks, and can exceed the PAGE_SIZE value which allows an unprivileged user to send a Netlink message that is associated with iSCSI, and has a length up to the maximum length of a Netlink message.

References