Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

De4Dcr0W

#34685of 56,330
7.8Total CVSS
Vulnerabilities · 1
PT-2021-2468
7.8
2021-02-13
Linux · Linux Kernel · CVE-2021-3444
**Name of the Vulnerable Software and Affected Versions** Linux kernel versions prior to 5.11.2 Linux kernel versions prior to 5.10.19 Linux kernel versions prior to 5.4.101 **Description** The bpf verifier in the Linux kernel did not properly handle mod32 destination register truncation when the source register was known to be 0. A local attacker with the ability to load bpf programs could use this to gain out-of-bounds reads in kernel memory, leading to information disclosure, and possibly out-of-bounds writes that could potentially lead to code execution. **Recommendations** For Linux kernel versions prior to 5.11.2, update to version 5.11.2 or later. For Linux kernel versions prior to 5.10.19, update to version 5.10.19 or later. For Linux kernel versions prior to 5.4.101, update to version 5.4.101 or later.