CVE-2021-31440
Summary
| CVE | CVE-2021-31440 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-05-21 15:15:00 UTC |
| Updated | 2023-08-11 19:53:00 UTC |
| Description | This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel 5.11.15. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of eBPF programs. The issue results from the lack of proper validation of user-supplied eBPF programs prior to executing them. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the kernel. Was ZDI-CAN-13661. |
NVD Known Affected Configurations (CPE 2.3)
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159492 Oracle Enterprise Linux Security Update for kernel (ELSA-2021-4356)
- 180577 Debian Security Update for linux (CVE-2021-31440)
- 198416 Ubuntu Security Notification for Linux kernel vulnerabilities (USN-4997-1)
- 198417 Ubuntu Security Notification for Linux kernel vulnerabilities (USN-4999-1)
- 198419 Ubuntu Security Notification for Linux kernel (OEM) vulnerabilities (USN-5001-1)
- 198426 Ubuntu Security Notification for Linux kernel (KVM) vulnerabilities (USN-4997-2)
- 239816 Red Hat Update for kernel security (RHSA-2021:4356)
- 239879 Red Hat Update for kernel-rt (RHSA-2021:4140)
- 353158 Amazon Linux Security Advisory for kernel : ALAS2KERNEL-5.10-2022-002
- 610418 Google Pixel Android June 2022 Security Patch Missing
- 940265 AlmaLinux Security Update for kernel (ALSA-2021:4356)