Skip to content

kernel CVE-2021-41864

Moderate
cbgbt published GHSA-2pq4-6c8j-v9xr Dec 4, 2021

Package

kernel (bottlerocket)

Affected versions

< 1.4.2

Patched versions

1.4.2

Description

An out-of-bounds memory write flaw was found in prealloc_elems_and_freelist in the bpf subsystem in the Linux kernel. A multiplication could lead to an integer overflow which could allow a local attacker, with a special user privilege, to gain access to out-of-bounds memory leading to a system crash or a leak of internal kernel information.

Severity

Moderate

CVE ID

CVE-2021-41864

Weaknesses

No CWEs