UBUNTU-CVE-2021-34556
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-34556
UBUNTU-CVE-2021-34556
Summary:
Details: In the Linux kernel through 5.13.7, an unprivileged BPF program can obtain sensitive information from kernel memory via a Speculative Store Bypass side-channel attack because the protection mechanism neglects the possibility of uninitialized memory locations on the BPF stack.
References: https://ubuntu.com/security/CVE-2021-34556, https://www.openwall.com/lists/oss-security/2021/08/01/3, https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=f5e81d1117501546b7be050c5fbafa6efd2c722c, https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=2039f26f3aca5b0e419b98f65dd36481337b86ee, https://ubuntu.com/security/notices/USN-5092-1, https://ubuntu.com/security/notices/USN-5092-2, https://ubuntu.com/security/notices/USN-5096-1, https://ubuntu.com/security/notices/USN-5115-1, https://ubuntu.com/security/notices/USN-5137-1, https://ubuntu.com/security/notices/USN-5137-2, https://www.cve.org/CVERecord?id=CVE-2021-34556
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/linux?arch=source&distro=esm-infra-legacy%2Ftrusty
Affected ranges
Type: ECOSYSTEM
Events:
