CVE-2021-35477
בינונית 5.5
תיאור (מקור, אנגלית)
In the Linux kernel through 5.13.7, an unprivileged BPF program can obtain sensitive information from kernel memory via a Speculative Store Bypass side-channel attack because a certain preempting store operation does not necessarily occur before a store operation that has an attacker-controlled value.
מדדים
- CVSS 3.1
-
5.5 (MEDIUM)
מקור הציון: NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N - CWE
- CWE-203
מוצרים מושפעים
linux: linux kernel; debian: debian linux; fedoraproject: fedora
קישורים
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=2… PatchVendor Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=f… PatchVendor Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=2… PatchVendor Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=f… PatchVendor Advisory
- https://lists.debian.org/debian-lts-announce/2021/10/msg00010.html Mailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorap…
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorap…
- https://www.openwall.com/lists/oss-security/2021/08/01/3 Mailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/10/msg00010.html Mailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorap…