Related Vulnerabilities: CVE-2021-3490  

A security issue was found in the Linux kernel. It was discovered that eBPF ALU32 bounds tracking for bitwise ops (AND, OR and XOR) did not update the 32-bit bounds, leading to out-of-bounds reads and writes in the kernel.

Severity Medium

Remote No

Type Arbitrary code execution

Description

A security issue was found in the Linux kernel.  It was discovered that eBPF ALU32 bounds tracking for bitwise ops (AND, OR and XOR) did not update the 32-bit bounds, leading to out-of-bounds reads and writes in the kernel.

AVG-1881 linux-hardened 5.11.19.hardened1-1 Medium Vulnerable

AVG-1880 linux-zen 5.12.2.zen2-1 Medium Vulnerable

AVG-1879 linux 5.12.2.arch4-1 Medium Vulnerable

AVG-1741 linux-lts 5.10.36-1 Medium Vulnerable

https://www.openwall.com/lists/oss-security/2021/05/11/11
https://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf.git/commit/?id=049c4e13714ecbca567b4d5f6d563f05d431c80e