Related Vulnerabilities: CVE-2021-28375  

An issue was discovered in the Linux kernel through 5.11.6. fastrpc_internal_invoke in drivers/misc/fastrpc.c does not prevent user applications from sending kernel RPC messages, aka CID-20c40794eb85. This is a related issue to CVE-2019-2308.

Severity Medium

Remote No

Type Insufficient validation

Description

An issue was discovered in the Linux kernel through 5.11.6. fastrpc_internal_invoke in drivers/misc/fastrpc.c does not prevent user applications from sending kernel RPC messages, aka CID-20c40794eb85. This is a related issue to CVE-2019-2308.

AVG-1688 linux-lts 5.10.23-1 Medium Vulnerable

AVG-1687 linux-hardened 5.11.6.hardened1-1 Medium Vulnerable

AVG-1686 linux-zen 5.11.6.zen1-1 Medium Vulnerable

AVG-1685 linux 5.11.6.arch4-1 Medium Vulnerable

https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=20c40794eb85ea29852d7bc37c55713802a543d6