CVE-2021-3489
CVSS v3.1
7.8 (High)
CVSS v2.0
7.2 (High)
EPSS
0.05 % (19th)
Affected Products
2
Advisories
14
The eBPF RINGBUF bpf_ringbuf_reserve() function in the Linux kernel did not check that the allocated size was smaller than the ringbuf size, allowing an attacker to perform out-of-bounds writes within the kernel and therefore, arbitrary code execution. This issue was fixed via commit 4b81ccebaeee ("bpf, ringbuf: Deny reserve of buffers larger than ringbuf") (v5.13-rc4) and backported to the stable kernels in v5.12.4, v5.11.21, and v5.10.37. It was introduced via 457f44363a88 ("bpf: Implement BPF ring buffer and verifier support for it") (v5.8-rc1).
Weaknesses
- CVE Status
- PUBLISHED
- CNA
- Canonical Ltd.
- Published Date
-
2021-06-04 02:15:07
(3 years ago) - Updated Date
-
2021-09-14 14:30:32
(3 years ago)
Affected Products
Loading...
Loading...
Loading...
Configuration #1
|
Configuration #2
|
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...