Skip to content

kernel CVE-2021-3491

High
tjkirch published GHSA-crg3-8994-x9c3 Jun 25, 2021

Package

kernel (bottlerocket)

Affected versions

< 1.1.2

Patched versions

1.1.2

Description

The io_uring subsystem allowed the MAX_RW_COUNT limit to be bypassed in the PROVIDE_BUFFERS operation, which led to negative values being used in mem_rw when reading /proc/PID/mem. This could be used to create a heap overflow leading to arbitrary code execution in the kernel.

Severity

High

CVE ID

CVE-2021-3491

Weaknesses

No CWEs