CVE-2021-43975 log

Source
Severity Medium
Remote No
Type Arbitrary code execution
Description
In the Linux kernel before version 5.15.7, hw_atl_utils_fw_rpc_wait in drivers/net/ethernet/aquantia/atlantic/hw_atl/hw_atl_utils.c allows an attacker (who can introduce a crafted device) to trigger an out-of-bounds write via a crafted length value.
Group Package Affected Fixed Severity Status Ticket
AVG-2613 linux-lts 5.10.83-1 5.10.84-1 Medium Fixed
AVG-2612 linux-hardened 5.15.6.hardened1-1 5.15.7.hardened1-1 Medium Fixed
AVG-2611 linux-zen 5.15.6.zen2-1 5.15.7.zen1-1 Medium Fixed
AVG-2610 linux 5.15.6.arch2-1 5.15.7.arch1-1 Medium Fixed
References
https://lore.kernel.org/netdev/163698540868.13805.17800408021782408762.git-patchwork-notify@kernel.org/T/
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?h=v5.15.7&id=cec49b6dfdb0b9fefd0f17c32014223f73ee2605
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?h=v5.10.84&id=2c514d25003ac89bb7716bb4402918ccb141f8f5