UBUNTU-CVE-2021-20268
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-20268
UBUNTU-CVE-2021-20268
Summary:
Details: An out-of-bounds access flaw was found in the Linux kernel's implementation of the eBPF code verifier in the way a user running the eBPF script calls dev_map_init_map or sock_map_alloc. This flaw allows a local user to crash the system or possibly escalate their privileges. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
References: https://ubuntu.com/security/CVE-2021-20268, https://www.zerodayinitiative.com/advisories/ZDI-21-101/, https://git.kernel.org/linus/bc895e8b2a64e502fbba72748d59618272052a8b, https://ubuntu.com/security/notices/USN-4910-1, https://www.cve.org/CVERecord?id=CVE-2021-20268
Affected packages
Package
Name: linux-hwe-edge
Purl: pkg:deb/ubuntu/[email protected]~16.04.1?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
