Skip to content

kernel CVE-2021-31829

Moderate
tjkirch published GHSA-9f3j-c23v-mp5f Jun 25, 2021

Package

kernel (bottlerocket)

Affected versions

< 1.1.2

Patched versions

1.1.2

Description

A flaw was found in the Linux kernel's eBPF verification code. By default, accessing the eBPF verifier is only accessible to privileged users with CAP_SYS_ADMIN. This flaw allows a local user who can insert eBPF instructions to use the eBPF verifier to abuse a spectre-like flaw and infer all system memory.

Severity

Moderate

CVE ID

CVE-2021-31829

Weaknesses

No CWEs