Description


BPF JIT compilers in the Linux kernel through 5.11.12 have incorrect computation of branch displacements, allowing them to execute arbitrary code within the kernel context. This affects arch/x86/net/bpf_jit_comp.c and arch/x86/net/bpf_jit_comp32.c.

References








https://news.ycombinator.com/item?id=26757760

Issue TrackingThird Party Advisory










https://news.ycombinator.com/item?id=26757760

Issue TrackingThird Party Advisory



Weaknesses



CWE-77

CVSS impact metrics


CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

7.8 · High

Information


Source identifier

[email protected]

Vulnerability status

Modified

Published

2021-04-08T19:15:13.580Z

5 years ago

Last modified

2024-11-21T05:00:47.650Z

1 year ago