VulnerabilityModified
CVE-2021-33624
In kernel/bpf/verifier.c in the Linux kernel before 5.12.13, a branch can be mispredicted (e.g., because of type confusion) and consequently an unprivileged BPF program can read arbitrary memory locations via a side-channel attack, aka CID-9183671af6db.
MEDIUM 4.7EPSS 0.92%
Does this matter?
Lower severity and a low EPSS score (0.92%). Track it; it rarely justifies an emergency change on its own.
Description
In kernel/bpf/verifier.c in the Linux kernel before 5.12.13, a branch can be mispredicted (e.g., because of type confusion) and consequently an unprivileged BPF program can read arbitrary memory locations via a side-channel attack, aka CID-9183671af6db.
- CVSS 3.1
- 4.7 MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.92% probability · 58th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-843
- Affected
- linux/linux kernel · debian/debian linux
- Source
- cve@mitre.org
References
- http://www.openwall.com/lists/oss-security/2021/06/21/1Exploit, Mailing List, Third Party Advisory
- https://github.com/benschlueter/CVE-2021-33624
- https://github.com/torvalds/linux/commit/9183671af6dbf60a1219371d4ed73e23f43b49dbPatch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/10/msg00010.htmlIssue Tracking, Third Party Advisory
- https://www.usenix.org/conference/usenixsecurity21/presentation/kirznerThird Party Advisory
- http://www.openwall.com/lists/oss-security/2021/06/21/1Exploit, Mailing List, Third Party Advisory
- https://github.com/torvalds/linux/commit/9183671af6dbf60a1219371d4ed73e23f43b49dbPatch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/10/msg00010.htmlIssue Tracking, Third Party Advisory
- https://www.usenix.org/conference/usenixsecurity21/presentation/kirznerThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.