CVE-2021-28361

Severity CVSS v4.0:
Pending analysis
Type:
CWE-476 NULL Pointer Dereference
Publication date:
13/03/2021
Last modified:
18/03/2021

Description

An issue was discovered in Storage Performance Development Kit (SPDK) before 20.01.01. If a PDU is sent to the iSCSI target with a zero length (but data is expected), the iSCSI target can crash with a NULL pointer dereference.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:spdk:storage_performance_development_kit:*:*:*:*:*:*:*:* 20.01.01 (excluding)


References to Advisories, Solutions, and Tools