CVE-2021-34556
בינונית 5.5
תיאור (מקור, אנגלית)
In the Linux kernel through 5.13.7, an unprivileged BPF program can obtain sensitive information from kernel memory via a Speculative Store Bypass side-channel attack because the protection mechanism neglects the possibility of uninitialized memory locations on the BPF stack.
מדדים
- CVSS 3.1
-
5.5 (MEDIUM)
מקור הציון: NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N - CWE
- CWE-203
מוצרים מושפעים
linux: linux kernel; fedoraproject: fedora; debian: debian linux
קישורים
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=2… PatchVendor Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=f… PatchVendor Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=2… PatchVendor Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=f… PatchVendor Advisory
- http://www.openwall.com/lists/oss-security/2021/08/01/3 Mailing List
- https://lists.debian.org/debian-lts-announce/2021/10/msg00010.html Mailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorap…
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorap…
- http://www.openwall.com/lists/oss-security/2021/08/01/3 Mailing List
- https://lists.debian.org/debian-lts-announce/2021/10/msg00010.html Mailing ListThird Party Advisory