CVE-2021-43975: Medium severity IBM Security Verify Governance, Identity Manager software component vulnerability
In the Linux kernel through 5.15.2, hwatlutilsfwrpcwait in drivers/net/ethernet/aquantia/atlantic/hwatl/hwatlutils.c allows an attacker (who can introduce a crafted device) to trigger an out-of-bounds write via a crafted length value.
Other sources
Linux Kernel could allow a local authenticated attacker to execute arbitrary code on the system, caused by an out-of-bounds write in hwatlutilsfwrpcwait in drivers/net/ethernet/aquantia/atlantic/hwatl/hwatlutils.c. By sending a specially-crafted length value using an emulate networking device, an attacker could exploit this vulnerability to execute arbitrary code or crash the system.
— IBM
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2021-43975?
CVE-2021-43975 is categorized as a high-severity vulnerability in the Linux kernel allowing for potential out-of-bounds write attacks.
How do I fix CVE-2021-43975?
To mitigate CVE-2021-43975, upgrade your Linux kernel to version 5.16 or later.
Which versions of the Linux kernel are affected by CVE-2021-43975?
CVE-2021-43975 affects the Linux kernel versions up to and including 5.15.2.
What types of systems are impacted by CVE-2021-43975?
CVE-2021-43975 impacts various systems using affected versions of the Linux kernel, such as Debian, Fedora, and Red Hat.
Can CVE-2021-43975 be exploited remotely?
CVE-2021-43975 requires an attacker to introduce a crafted device for exploitation, making remote exploitation unlikely.