CVE-2021-27365Patch(debian / cloud_backup)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch debian cloud_backup systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An issue was discovered in the Linux kernel through 5.11.3. Certain iSCSI data structures do not have appropriate length constraints or checks, and can exceed the PAGE_SIZE value. An unprivileged user can send a Netlink message that is associated with iSCSI, and has a length up to the maximum length of a Netlink message.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cloud_backup
  • debian_linux
  • linux_kernel
  • solidfire_baseboard_management_controller

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Products
cloud_backupdebian_linuxlinux_kernelsolidfire_baseboard_management_controllersolidfire_baseboard_management_controller_firmwaretekelec_platform_distribution

2 versions affected across 6 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-20: 1Patch / Workaround · 2026-02-20: 1Technical Details · 2026-02-20: 102-20
Signal classification1 categories
Patch
1100.0%
Full discourse1 post
  • Javier García Prieto@PenguinCityMx
    Patch

    @0xor0ne Yes, the CVE-2021-27365 vulnerability in the Linux kernel's iSCSI subsystem has been corrected. It was patched shortly after its discovery in March 2021 via kernel commits that added proper length checks and constraints to prevent the heap buffer overflow.

    Post summary

    CVE-2021-27365, a heap buffer overflow in the Linux kernel iSCSI subsystem, was fixed shortly after discovery with kernel commits adding proper length checks.

    0000028
    13 followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
OSdebiandebian_linux9.0--
OSlinuxlinux_kernel---
Appnetappcloud_backup---
HWnetappsolidfire_baseboard_management_controller---
OSnetappsolidfire_baseboard_management_controller_firmware---
Apporacletekelec_platform_distribution---

Explore more