A flaw was found in s390 eBPF JIT in bpf_jit_insn in arch/s390/net/bpf_jit_comp.c in the Linux kernel. In this flaw, a local attacker with special user privilege can circumvent the verifier and may lead to a confidentiality problem.
References
Link | Resource |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=2010090 | Issue Tracking Third Party Advisory |
https://lore.kernel.org/bpf/20210902185229.1840281-1-johan.almbladh@anyfinetworks.com/ | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Information
Published : 2022-02-18 10:15
Updated : 2022-03-03 06:43
NVD link : CVE-2021-20320
Mitre link : CVE-2021-20320
JSON object : View
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Products Affected
fedoraproject
- fedora
redhat
- enterprise_linux
linux
- linux_kernel