Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

De4Dcr0W

#33160of 53,639
7.8Total CVSS
Vulnerabilities · 1
PT-2021-2468
7.8
2021-02-13
Linux · Linux Kernel · CVE-2021-3444
**Name of the Vulnerable Software and Affected Versions** Linux kernel versions prior to 5.11.2 Linux kernel versions prior to 5.10.19 Linux kernel versions prior to 5.4.101 **Description** The bpf verifier in the Linux kernel did not properly handle mod32 destination register truncation when the source register was known to be 0. A local attacker with the ability to load bpf programs could use this to gain out-of-bounds reads in kernel memory, leading to information disclosure, and possibly out-of-bounds writes that could potentially lead to code execution. **Recommendations** For Linux kernel versions prior to 5.11.2, update to version 5.11.2 or later. For Linux kernel versions prior to 5.10.19, update to version 5.10.19 or later. For Linux kernel versions prior to 5.4.101, update to version 5.4.101 or later.