CVE-2021-20194 – There is a vulnerability in the linux kernel versions higher than 5.2 (if kernel compiled …

Vuln ID: CVE-2021-20194

Published:  2021-02-23  23:15:13Z

Description: There is a vulnerability in the linux kernel versions higher than 5.2 (if kernel compiled with config params CONFIG_BPF_SYSCALL=y , CONFIG_BPF=y , CONFIG_CGROUPS=y , CONFIG_CGROUP_BPF=y , CONFIG_HARDENED_USERCOPY not set, and BPF hook to getsockopt is registered). As result of BPF execution, the local user can trigger bug in __cgroup_bpf_run_filter_getsockopt() function that can lead to heap overflow (because of non-hardened usercopy). The impact of attack could be deny of service or possibly privileges escalation.

Source: NVD.NIST.GOV

 


Date:

Categorie(s):

Tag(s):