UBUNTU-CVE-2021-20194
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-20194
UBUNTU-CVE-2021-20194
Summary:
Details: There is a vulnerability in the linux kernel versions higher than 5.2 (if kernel compiled with config params CONFIG_BPF_SYSCALL=y , CONFIG_BPF=y , CONFIG_CGROUPS=y , CONFIG_CGROUP_BPF=y , CONFIG_HARDENED_USERCOPY not set, and BPF hook to getsockopt is registered). As result of BPF execution, the local user can trigger bug in __cgroup_bpf_run_filter_getsockopt() function that can lead to heap overflow (because of non-hardened usercopy). The impact of attack could be deny of service or possibly privileges escalation.
References: https://ubuntu.com/security/CVE-2021-20194, https://bugzilla.redhat.com/show_bug.cgi?id=1912683, https://patchwork.kernel.org/project/netdevbpf/patch/[email protected]/#23921223, https://ubuntu.com/security/notices/USN-4879-1, https://ubuntu.com/security/notices/USN-4884-1, https://ubuntu.com/security/notices/USN-4909-1, https://ubuntu.com/security/notices/USN-4912-1, https://www.cve.org/CVERecord?id=CVE-2021-20194
Affected packages
Package
Name: linux-hwe-edge
Purl: pkg:deb/ubuntu/linux-hwe-edge?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
