UBUNTU-CVE-2021-4001
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-4001
UBUNTU-CVE-2021-4001
Summary:
Details: A race condition was found in the Linux kernel's ebpf verifier between bpf_map_update_elem and bpf_map_freeze due to a missing lock in kernel/bpf/syscall.c. In this flaw, a local user with a special privilege (cap_sys_admin or cap_bpf) can modify the frozen mapped address space. This flaw affects kernel versions prior to 5.16 rc2.
References: https://ubuntu.com/security/CVE-2021-4001, https://git.kernel.org/linus/353050be4c19e102178ccc05988101887c25ae53, https://ubuntu.com/security/notices/USN-5207-1, https://ubuntu.com/security/notices/USN-5265-1, https://ubuntu.com/security/notices/USN-5278-1, https://ubuntu.com/security/notices/USN-6417-1, https://www.cve.org/CVERecord?id=CVE-2021-4001
Affected packages
Package
Name: linux-hwe-edge
Purl: pkg:deb/ubuntu/[email protected]~16.04.1?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
