Skip to content

kernel CVE-2021-29154

Moderate
tjkirch published GHSA-6wm6-4q22-q7mf Jun 25, 2021

Package

kernel (bottlerocket)

Affected versions

< 1.1.2

Patched versions

1.1.2

Description

A flaw was found in the Linux kernel eBPF implementation. By default, accessing the eBPF verifier is only accessible to privileged users with CAP_SYS_ADMIN. A local user with the ability to insert eBPF instructions can abuse a flaw in eBPF to corrupt memory.

Severity

Moderate

CVE ID

CVE-2021-29154

Weaknesses

No CWEs