PT-2021-4221 · Linux+8 · Linux Kernel+8

Ga_Ryo

+1

·

Published

2021-05-11

·

Updated

2024-06-15

·

CVE-2021-3489

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to v5.13-rc4 Linux kernel versions prior to v5.12.4 Linux kernel versions prior to v5.11.21 Linux kernel versions prior to v5.10.37
Description The eBPF RINGBUF bpf ringbuf reserve() function in the Linux kernel did not check that the allocated size was smaller than the ringbuf size, allowing an attacker to perform out-of-bounds writes within the kernel and therefore, arbitrary code execution. This issue allows an attacker to execute arbitrary code in the context of the kernel.
Recommendations For Linux kernel versions prior to v5.13-rc4, update to v5.13-rc4 or later to fix the issue. For Linux kernel versions prior to v5.12.4, update to v5.12.4 or later to fix the issue. For Linux kernel versions prior to v5.11.21, update to v5.11.21 or later to fix the issue. For Linux kernel versions prior to v5.10.37, update to v5.10.37 or later to fix the issue.

Fix

Buffer Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2021:4356
ALT-PU-2021-1805
ALT-PU-2021-1833
ALT-PU-2021-1855
ALT-PU-2021-1888
ALT-PU-2021-1896
ALT-PU-2021-1912
ALT-PU-2021-1920
ALT-PU-2021-1961
ALT-PU-2021-1985
ALT-PU-2021-1990
ALT-PU-2021-2293
ALT-PU-2021-2305
ALT-PU-2021-2307
ALT-PU-2021-3481
BDU:2021-04825
CESA-2021_4140
CESA-2021_4356
CVE-2021-3489
OPENSUSE-SU-2021:1975-1
OPENSUSE-SU-2021:1977-1
OPENSUSE-SU-2021_1975-1
OPENSUSE-SU-2021_1977-1
OPENSUSE-SU-2024:10728-1
OPENSUSE-SU-2024:13704-1
RHSA-2021:4140
RHSA-2021:4356
RHSA-2021_4140
RHSA-2021_4356
SUSE-SU-2021:1975-1
SUSE-SU-2021:1977-1
SUSE-SU-2021:2198-1
USN-4948-1
USN-4949-1
USN-4950-1
ZDI-21-590

Affected Products

Alt Linux
Almalinux
Centos
Linuxmint
Linux Kernel
Red Hat
Red Os
Suse
Ubuntu