Description
There is a vulnerability in the linux kernel versions higher than 5.2 (if kernel compiled with config params CONFIG_BPF_SYSCALL=y , CONFIG_BPF=y , CONFIG_CGROUPS=y , CONFIG_CGROUP_BPF=y , CONFIG_HARDENED_USERCOPY not set, and BPF hook to getsockopt is registered). As result of BPF execution, the local user can trigger bug in __cgroup_bpf_run_filter_getsockopt() function that can lead to heap overflow (because of non-hardened usercopy). The impact of attack could be deny of service or possibly privileges escalation.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-7641 | There is a vulnerability in the linux kernel versions higher than 5.2 (if kernel compiled with config params CONFIG_BPF_SYSCALL=y , CONFIG_BPF=y , CONFIG_CGROUPS=y , CONFIG_CGROUP_BPF=y , CONFIG_HARDENED_USERCOPY not set, and BPF hook to getsockopt is registered). As result of BPF execution, the local user can trigger bug in __cgroup_bpf_run_filter_getsockopt() function that can lead to heap overflow (because of non-hardened usercopy). The impact of attack could be deny of service or possibly privileges escalation. |
Ubuntu USN |
USN-4879-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-4884-1 | Linux kernel (OEM) vulnerabilities |
Ubuntu USN |
USN-4909-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-4912-1 | Linux kernel (OEM) vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-03T17:30:07.585Z
Reserved: 2020-12-17T00:00:00.000Z
Link: CVE-2021-20194
No data.
Status : Modified
Published: 2021-02-23T23:15:13.100
Modified: 2024-11-21T05:46:06.407
Link: CVE-2021-20194
OpenCVE Enrichment
No data.
EUVD
Ubuntu USN