Wind River Support Network

HomeDefectsLIN1021-234
Fixed

LIN1021-234 : Security Advisory - linux - CVE-2021-31440

Created: May 23, 2021    Updated: May 30, 2021
Resolved Date: May 25, 2021
Found In Version: 10.21.20.1
Fix Version: 10.21.20.1
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Kernel

Description

This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel 5.11.15. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of eBPF programs. The issue results from the lack of proper validation of user-supplied eBPF programs prior to executing them. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the kernel. Was ZDI-CAN-13661.

CREATE(Triage):(User=admin) CVE-2021-31440 (https://nvd.nist.gov/vuln/detail/CVE-2021-31440)

CVEs


Live chat
Online