Skip to content

kernel CVE-2021-44733

Moderate
cbgbt published GHSA-vhpv-55cp-2cw3 Jan 26, 2022

Package

kernel (bottlerocket)

Affected versions

< 1.5.3

Patched versions

1.5.3

Description

A use-after-free flaw in the Linux kernel TEE (Trusted Execution Environment) subsystem was found in the way user calls ioctl TEE_IOC_OPEN_SESSION or TEE_IOC_INVOKE. A local user could use this flaw to crash the system or escalate their privileges on the system. If the Linux system is not configured with the CONFIG_PREEMPT option or CONFIG_CPU_SW_DOMAIN_PAN option enabled, then it is unlikely that a user can trigger this issue.

Severity

Moderate

CVE ID

CVE-2021-44733

Weaknesses

No CWEs