CVE-2021-20194
Summary
| CVE | CVE-2021-20194 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-02-23 23:15:00 UTC |
| Updated | 2023-02-12 22:15:00 UTC |
| Description | There is a vulnerability in the linux kernel versions higher than 5.2 (if kernel compiled with config params CONFIG_BPF_SYSCALL=y , CONFIG_BPF=y , CONFIG_CGROUPS=y , CONFIG_CGROUP_BPF=y , CONFIG_HARDENED_USERCOPY not set, and BPF hook to getsockopt is registered). As result of BPF execution, the local user can trigger bug in __cgroup_bpf_run_filter_getsockopt() function that can lead to heap overflow (because of non-hardened usercopy). The impact of attack could be deny of service or possibly privileges escalation. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Red Hat Customer Portal - Access to 24x7 support and knowledge |
MISC |
access.redhat.com |
|
| 1912683 – (CVE-2021-20194) CVE-2021-20194 kernel: heap overflow in __cgroup_bpf_run_filter_getsockopt() |
MISC |
bugzilla.redhat.com |
Issue Tracking, Patch, Third Party Advisory |
| Red Hat Customer Portal - Access to 24x7 support and knowledge |
MISC |
access.redhat.com |
|
| Red Hat Customer Portal - Access to 24x7 support and knowledge |
MISC |
access.redhat.com |
|
| CVE-2021-20194 Linux Kernel Vulnerability in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159492 Oracle Enterprise Linux Security Update for kernel (ELSA-2021-4356)
- 179880 Debian Security Update for linux (CVE-2021-20194)
- 198298 Ubuntu Security Notification for Linux, Linux-aws, Linux-azure, Linux-gcp, Linux-hwe-5.8, Linux-kvm, (USN-4879-1)
- 198304 Ubuntu Security Notification for Linux-oem-5.10 Vulnerabilities (USN-4884-1)
- 198325 Ubuntu Security Notification for Linux kernel vulnerabilities (USN-4909-1)
- 198328 Ubuntu Security Notification for Linux kernel (OEM) vulnerabilities (USN-4912-1)
- 239816 Red Hat Update for kernel security (RHSA-2021:4356)
- 239879 Red Hat Update for kernel-rt (RHSA-2021:4140)
- 900084 CBL-Mariner Linux Security Update for kernel 5.10.52.1
- 900302 CBL-Mariner Linux Security Update for kernel 5.10.57.1
- 900318 CBL-Mariner Linux Security Update for kernel 5.10.60.1
- 901493 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (6529-1)
- 902698 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (3908-1)
- 905870 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (3908-2)
- 906476 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (6529-2)
- 940265 AlmaLinux Security Update for kernel (ALSA-2021:4356)