Wind River Support Network

HomeDefectsLIN1021-305
Fixed

LIN1021-305 : Security Advisory - linux - CVE-2021-31440

Created: May 24, 2021    Updated: Nov 14, 2022
Resolved Date: May 25, 2021
Found In Version: 10.21.20.1
Fix Version: 10.21.20.1
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Kernel

Description

This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel 5.11.15. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of eBPF programs. The issue results from the lack of proper validation of user-supplied eBPF programs prior to executing them. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the kernel. Was ZDI-CAN-13661.

CREATE(Triage):(User=admin) CVE-2021-31440 (https://nvd.nist.gov/vuln/detail/CVE-2021-31440)

CVEs


Live chat
Online