← volver
CVE-2021-3490highCWE-20CWE-787

Linux kernel eBPF bitwise ops ALU32 bounds tracking

41Vexday Risk Score

Corrige pronto. Ella tiene exploit funcional público.

ssvc Attendcvss 7.8epss 27%
de la publicación al arma0 días
Publicada en NVD4 jun
metasploit11 may
probabilidad de explotación
27%top 2% de las CVE
explotación observada
noninguna fuente lo reporta
En resumen

Un defecto en el kernel Linux permitió que las operaciones bitwise (AND, OR, XOR) en eBPF no actualizaran correctamente los límites de memoria, posibilitando lectura y escritura fuera de los límites y ejecución arbitraria de código.

Detalle técnico

El verificador eBPF ALU32 en el kernel Linux no actualizaba correctamente los límites de 32 bits después de operaciones bitwise, permitiendo acceso a memoria fuera de los límites. Un atacante con capacidad de cargar programas eBPF puede crear un programa malicioso para eludir verificaciones de límites y lograr ejecución de código en el kernel.

Resumen generado y traducido por IA a partir de la descripción oficial.
The eBPF ALU32 bounds tracking for bitwise ops (AND, OR and XOR) in the Linux kernel did not properly update 32-bit bounds, which could be turned into out of bounds reads and writes in the Linux kernel and therefore, arbitrary code execution. This issue was fixed via commit 049c4e13714e ("bpf: Fix alu32 const subreg bound tracking on bitwise operations") (v5.13-rc4) and backported to the stable kernels in v5.12.4, v5.11.21, and v5.10.37. The AND/OR issues were introduced by commit 3f50f132d840 ("bpf: Verifier, do explicit ALU32 bounds tracking") (5.7-rc1) and the XOR variant was introduced by 2921c90d4718 ("bpf:Fix a verifier failure with xor") ( 5.10-rc1).
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Productos afectados
Linux · Linux kernel