All errata/c9f1/ALT-PU-2021-4858-1
ALT-PU-2021-4858-1

Package update kernel-image-std-def in branch c9f1

Version5.4.98-alt0.c9f
Published2021-02-19
Max severityHIGH
Severity:

Closed issues (2)

BDU:2021-03254
HIGH7.8

Уязвимость подсистемы eBPF ядра операционной системы Linux, позволяющая нарушителю выполнить произвольный код

Published: 2021-06-25Modified: 2025-01-29
CVSS 3.xHIGH 7.8
CVSS:3.x/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.0MEDIUM 6.8
CVSS:2.0/AV:L/AC:L/Au:S/C:C/I:C/A:C
References
CVE-2021-3600
HIGH7.8

It was discovered that the eBPF implementation in the Linux kernel did not properly track bounds information for 32 bit registers when performing div and mod operations. A local attacker could use this to possibly execute arbitrary code.

Published: 2024-01-08Modified: 2024-11-21
CVSS 3.xHIGH 7.8
CVSS:3.x/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H