Vulnerability Name: | CVE-2021-31829 (CCN-201175) | ||||||||||||||||||
Assigned: | 2021-04-30 | ||||||||||||||||||
Published: | 2021-04-30 | ||||||||||||||||||
Updated: | 2022-01-01 | ||||||||||||||||||
Summary: | kernel/bpf/verifier.c in the Linux kernel through 5.12.1 performs undesirable speculative loads, leading to disclosure of stack content via side-channel attacks, aka CID-801c6058d14a. The specific concern is not protecting the BPF stack area against speculative loads. Also, the BPF stack can contain uninitialized data that might represent sensitive information previously operated on by the kernel. | ||||||||||||||||||
CVSS v3 Severity: | 5.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N) 4.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
4.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
5.4 Medium (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
| ||||||||||||||||||
CVSS v2 Severity: | 2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||||||||||||
Vulnerability Type: | CWE-863 CWE-200 | ||||||||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2021-31829 Source: MISC Type: Mailing List, Patch, Third Party Advisory http://www.openwall.com/lists/oss-security/2021/05/04/4 Source: XF Type: UNKNOWN linux-kernel-cve202131829-info-disc(201175) Source: CCN Type: Linux Kernel GIT Repository bpf: Fix leakage of uninitialized bpf stack under speculation Source: CCN Type: Linux Kernel GIT Repository bpf: Fix masking negation logic upon negative dst register Source: MISC Type: Patch, Third Party Advisory https://github.com/torvalds/linux/commit/801c6058d14a82179a7ee17a4b532cac6fad067f Source: MLIST Type: Mailing List, Third Party Advisory [debian-lts-announce] 20210623 [SECURITY] [DLA 2690-1] linux-4.19 security update Source: FEDORA Type: Mailing List, Third Party Advisory FEDORA-2021-5ad5249c43 Source: FEDORA Type: Mailing List, Third Party Advisory FEDORA-2021-9c0276e935 Source: FEDORA Type: Mailing List, Third Party Advisory FEDORA-2021-7c085ca697 Source: CCN Type: oss-sec Mailing List, Tue, 4 May 2021 11:06:52 +0100 [CVE-2021-31829] Linux kernel protection of stack pointer against speculative pointer arithmetic can be bypassed to leak content of kernel memory | ||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration 3: Configuration RedHat 1: Configuration RedHat 2: Configuration RedHat 3: Configuration RedHat 4: Configuration RedHat 5: Configuration RedHat 6: ![]() | ||||||||||||||||||
Oval Definitions | |||||||||||||||||||
| |||||||||||||||||||
BACK |