CVE-2021-33200
Summary
| CVE | CVE-2021-33200 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-05-27 13:15:00 UTC |
| Updated | 2023-11-07 03:35:00 UTC |
| Description | kernel/bpf/verifier.c in the Linux kernel through 5.12.7 enforces incorrect limits for pointer arithmetic operations, aka CID-bb01a1bba579. This can be abused to perform out-of-bounds reads and writes in kernel memory, leading to local privilege escalation to root. In particular, there is a corner case where the off reg causes a masking direction change, which then results in an incorrect final aux->alu_limit. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 34 Update: kernel-5.12.8-300.fc34 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 33 Update: kernel-5.12.8-200.fc33 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| CVE-2021-33200 Linux Kernel Vulnerability in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
|
| [SECURITY] Fedora 33 Update: kernel-5.12.8-200.fc33 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| oss-security - [CVE-2021-33200] Linux kernel enforcing incorrect limits for pointer
arithmetic operations by BPF verifier can be abused to perform out-of-bounds
reads and writes in kernel memory |
MISC |
www.openwall.com |
|
| [SECURITY] Fedora 34 Update: kernel-5.12.8-300.fc34 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159492 Oracle Enterprise Linux Security Update for kernel (ELSA-2021-4356)
- 180538 Debian Security Update for linux (CVE-2021-33200)
- 198402 Ubuntu Security Notification for Linux kernel (OEM) vulnerabilities (USN-4983-1)
- 198416 Ubuntu Security Notification for Linux kernel vulnerabilities (USN-4997-1)
- 198417 Ubuntu Security Notification for Linux kernel vulnerabilities (USN-4999-1)
- 198418 Ubuntu Security Notification for Linux kernel vulnerabilities (USN-5000-1)
- 198425 Ubuntu Security Notification for Linux kernel (KVM) vulnerabilities (USN-5000-2)
- 198426 Ubuntu Security Notification for Linux kernel (KVM) vulnerabilities (USN-4997-2)
- 198459 Ubuntu Security Notification for Linux, Linux-aws, Linux-aws-hwe, Linux-azure, Linux-azure-4.15, Linux-gcp, (USN-5018-1)
- 239816 Red Hat Update for kernel security (RHSA-2021:4356)
- 239879 Red Hat Update for kernel-rt (RHSA-2021:4140)
- 281096 Fedora Security Update for kernel (FEDORA-2021-646098b5b8)
- 281097 Fedora Security Update for kernel (FEDORA-2021-0b35886add)
- 281487 Fedora Security Update for kernel (FEDORA-2021-646098b5b8)
- 281488 Fedora Security Update for kernel (FEDORA-2021-0b35886add)
- 352461 Amazon Linux Security Advisory for kernel: ALAS2-2021-1675
- 352475 Amazon Linux Security Advisory for kernel: ALAS-2021-1516
- 352498 Amazon Linux Security Advisory for kernel-livepatch: ALAS2LIVEPATCH-2021-054
- 610384 Google Pixel Android December 2021 Security Patch Missing
- 670514 EulerOS Security Update for kernel (EulerOS-SA-2021-2272)
- 670543 EulerOS Security Update for kernel (EulerOS-SA-2021-2301)
- 670796 EulerOS Security Update for kernel (EulerOS-SA-2021-2554)
- 750117 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2021:1891-1)
- 750118 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2021:1890-1)
- 750121 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2021:1888-1)
- 750125 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2021:1887-1)
- 750126 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2021:1889-1)
- 750139 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2021:1913-1)
- 750140 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2021:1912-1)
- 750171 OpenSUSE Security Update for the Linux Kernel (openSUSE-SU-2021:0843-1)
- 750650 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2021:1975-1)
- 750652 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2021:1977-1)
- 750674 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 18 for SLE 12 SP5) (SUSE-SU-2021:2020-1)
- 750676 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 13 for SLE 15 SP2) (SUSE-SU-2021:2027-1)
- 750678 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 24 for SLE 15) (SUSE-SU-2021:2057-1)
- 750741 OpenSUSE Security Update for the Linux Kernel (openSUSE-SU-2021:0947-1)
- 750762 OpenSUSE Security Update for the Linux Kernel (openSUSE-SU-2021:1977-1)
- 750766 OpenSUSE Security Update for the Linux Kernel (openSUSE-SU-2021:1975-1)
- 750864 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2021:2421-1)
- 750868 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2021:2427-1)
- 750869 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2021:2422-1)
- 750877 OpenSUSE Security Update for the Linux Kernel (openSUSE-SU-2021:2427-1)
- 755988 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2024:0975-1)
- 756005 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2024:0925-1)
- 900096 CBL-Mariner Linux Security Update for kernel 5.10.52.1
- 900304 CBL-Mariner Linux Security Update for kernel 5.10.57.1
- 900319 CBL-Mariner Linux Security Update for kernel 5.10.60.1
- 901733 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (6563-1)
- 902919 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (4244)
- 905960 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (4244-1)
- 940265 AlmaLinux Security Update for kernel (ALSA-2021:4356)