PT-2024-11058 · Linux+1 · Linux Kernel+1

Published

2021-04-16

·

Updated

2024-08-19

·

CVE-2021-46908

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to the use of correct permission flags for mixed signed bounds arithmetic in the Linux kernel's bpf. It involves forbidding the addition of unknown scalars with mixed signed bounds due to Spectre v1 masking mitigation, requiring the bypass spec v1 flag instead of allow ptr leaks.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-02864
CVE-2021-46908
OPENSUSE-SU-2024_1489-1
SUSE-SU-2024:1465-1
SUSE-SU-2024:1489-1

Affected Products

Linux Kernel
Suse