Description
An issue was discovered in the Linux kernel before 5.11.8. kernel/bpf/verifier.c performs undesirable out-of-bounds speculation on pointer arithmetic, leading to side-channel attacks that defeat Spectre mitigations and obtain sensitive information from kernel memory, aka CID-f232326f6966. This affects pointer types that do not define a ptr_limit.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2610-1 | linux-4.19 security update |
EUVD |
EUVD-2020-19694 | An issue was discovered in the Linux kernel before 5.11.8. kernel/bpf/verifier.c performs undesirable out-of-bounds speculation on pointer arithmetic, leading to side-channel attacks that defeat Spectre mitigations and obtain sensitive information from kernel memory, aka CID-f232326f6966. This affects pointer types that do not define a ptr_limit. |
Ubuntu USN |
USN-4887-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-4890-1 | Linux kernel vulnerabilities |
References
History
Thu, 08 Oct 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-10-08T21:03:24.204Z
Reserved: 2020-10-16T00:00:00.000Z
Link: CVE-2020-27170
Updated: 2024-08-04T16:11:35.904Z
Status : Modified
Published: 2021-03-20T22:15:11.940
Modified: 2026-10-08T21:17:27.047
Link: CVE-2020-27170
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Ubuntu USN