QID 352503
Date Published: 2021-08-11
QID 352503: Amazon Linux Security Advisory for kernel: ALAS2-2021-1696
A flaw was found in the linux kernel, where an unprivileged bpf program can obtain sensitive information from kernel memory via a speculative store bypass side-channel attack.
This issue occurs when the protection mechanism neglects the possibility of uninitialized memory locations on the bpf stack.
The highest threat from this vulnerability is to confidentiality. (
( CVE-2021-34556) a flaw in the linux kernel allows a privileged bpf program to obtain sensitive information from kernel memory via a speculative store bypass side-channel in the ebpf subsystem (cve-2021-35477) a vulnerability was found in the linux kernel.
Missing size validations on inbound sctp packets may allow the kernel to read uninitialized memory. (
( CVE-2021-3655)
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
Allows unauthorized disclosure of information; allows unauthorized modification; allows disruption of service.
- ALAS2-2021-1696 -
alas.aws.amazon.com/AL2/ALAS-2021-1696.html
CVEs related to QID 352503
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ALAS2-2021-1696 | Amazon Linux 2 |
|