Wind River Support Network

HomeDefectsLIN1019-6488
Fixed

LIN1019-6488 : Security Advisory - linux - CVE-2021-31829

Created: May 9, 2021    Updated: Jul 13, 2021
Resolved Date: Jun 3, 2021
Found In Version: 10.19.45.1
Fix Version: 10.19.45.17
Severity: Standard
Applicable for: Wind River Linux LTS 19
Component/s: Kernel

Description

kernel/bpf/verifier.c in the Linux kernel through 5.12.1 performs undesirable speculative loads, leading to disclosure of stack content via side-channel attacks, aka CID-801c6058d14a. The specific concern is not protecting the BPF stack area against speculative loads. Also, the BPF stack can contain uninitialized data that might represent sensitive information previously operated on by the kernel.

CREATE(Triage):(User=admin) [CVE-2021-31829|https://nvd.nist.gov/vuln/detail/CVE-2021-31829]

CVEs


Live chat
Online