CVE-2021-27365

Related Vulnerabilities: CVE-2021-27365  

A flaw was found in the Linux kernel. An out-of-bounds read was discovered in the libiscsi module that could lead to reading kernel memory or a crash. The highest threat from this vulnerability is to data confidentiality as well as system availability.

Description

A flaw was found in the Linux kernel. An out-of-bounds read was discovered in the libiscsi module that could lead to reading kernel memory or a crash. The highest threat from this vulnerability is to data confidentiality as well as system availability.

Statement

Red Hat Product Security is aware of this issue. Updates will be released as they become available.

Red Hat Product Security is aware of this issue. Updates will be released as they become available.

Mitigation

The LIBISCSI module will be auto-loaded when required, its use can be disabled by preventing the module from loading with the following instructions:

# echo "install libiscsi /bin/true" >> /etc/modprobe.d/disable-libiscsi.conf

The system will need to be restarted if the libiscsi modules are loaded. In most circumstances, the libiscsi kernel modules will be unable to be unloaded while any network interfaces are active and the protocol is in use.

If the system requires iscsi to work correctly, this mitigation may not be suitable.

If you need further assistance, see KCS article https://access.redhat.com/solutions/41278 or contact Red Hat Global Support Services.

Additional Information

  • Bugzilla 1930080: CVE-2021-27365 kernel: out-of-bounds read in libiscsi module
  • (CWE-200|CWE-125): Exposure of Sensitive Information to an Unauthorized Actor or Out-of-bounds Read
  • FAQ: Frequently asked questions about CVE-2021-27365