← Back to browse · API

CVE-2021-42252

Severity
HIGH
CVSS
7.8
EPSS
0.0037
Risk score
31.33
CISA KEV
No
PoC
No
Published
2021-10-11
Modified
2026-08-05
First seen
2026-08-06
Aliases
-
Products
linux:linux_kernel, netapp:cloud_backup, netapp:h300e, netapp:h300e_firmware, netapp:h300s, netapp:h300s_firmware, netapp:h410c, netapp:h410c_firmware, netapp:h410s, netapp:h410s_firmware, netapp:h500e, netapp:h500e_firmware, netapp:h500s, netapp:h500s_firmware, netapp:h700e, netapp:h700e_firmware, netapp:h700s, netapp:h700s_firmware, netapp:solidfire_baseboard_management_controller, netapp:solidfire_baseboard_management_controller_firmware
Sources
nvd CVE-2021-42252

Description

An issue was discovered in aspeed_lpc_ctrl_mmap in drivers/soc/aspeed/aspeed-lpc-ctrl.c in the Linux kernel before 5.14.6. Local attackers able to access the Aspeed LPC control interface could overwrite memory in the kernel and potentially execute privileges, aka CID-b49a0e69a7b1. This occurs because a certain comparison uses values that are not memory sizes.

References