PT-2021-4236 · Linux+5 · Linux Kernel+5

Manfp

+1

·

Published

2021-05-11

·

Updated

2025-09-29

·

CVE-2021-3490

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.13-rc4 Linux kernel versions 5.7-rc1 through 5.12.3 Linux kernel versions 5.10-rc1 through 5.10.36 Linux kernel versions 5.11 through 5.11.20
Description The eBPF ALU32 bounds tracking for bitwise ops (AND, OR and XOR) in the Linux kernel did not properly update 32-bit bounds, which could be turned into out of bounds reads and writes in the Linux kernel and therefore, arbitrary code execution. This issue is related to a buffer overflow in memory, allowing an attacker to execute arbitrary code in the context of the kernel.
Recommendations For Linux kernel versions prior to 5.13-rc4, update to version 5.13-rc4 or later. For Linux kernel versions 5.7-rc1 through 5.12.3, update to version 5.12.4 or later. For Linux kernel versions 5.10-rc1 through 5.10.36, update to version 5.10.37 or later. For Linux kernel versions 5.11 through 5.11.20, update to version 5.11.21 or later. As a temporary workaround, consider disabling the eBPF functionality until a patch is available.

Exploit

Fix

RCE

Out of bounds Read

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2021-1805
ALT-PU-2021-1833
ALT-PU-2021-1855
ALT-PU-2021-1888
ALT-PU-2021-1896
ALT-PU-2021-1912
ALT-PU-2021-1920
ALT-PU-2021-1961
ALT-PU-2021-1985
ALT-PU-2021-1990
ALT-PU-2021-2293
ALT-PU-2021-2305
ALT-PU-2021-2307
ALT-PU-2021-3481
BDU:2021-04842
CVE-2021-3490
OPENSUSE-SU-2021:1975-1
OPENSUSE-SU-2021:1977-1
OPENSUSE-SU-2021_1975-1
OPENSUSE-SU-2021_1977-1
OPENSUSE-SU-2024:10728-1
OPENSUSE-SU-2024:13704-1
SUSE-SU-2021:1975-1
SUSE-SU-2021:1977-1
SUSE-SU-2021:2198-1
SUSE-SU-2021_2198-1
USN-4948-1
USN-4949-1
USN-4950-1
ZDI-21-606

Affected Products

Alt Linux
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu