Related Vulnerabilities: CVE-2021-38166  

In kernel/bpf/hashtab.c in the Linux kernel through 5.13.8, there is an integer overflow and out-of-bounds write when many elements are placed in a single bucket. NOTE: exploitation might be impractical without the CAP_SYS_ADMIN capability.

Severity Medium

Remote No

Type Arbitrary code execution

Description

In kernel/bpf/hashtab.c in the Linux kernel through 5.13.8, there is an integer overflow and out-of-bounds write when many elements are placed in a single bucket. NOTE: exploitation might be impractical without the CAP_SYS_ADMIN capability.

AVG-1881 linux-hardened 5.12.19.hardened1-1 Medium Vulnerable

AVG-1880 linux-zen 5.13.8.zen1-1 Medium Vulnerable

AVG-1879 linux 5.13.8.arch4-1 Medium Vulnerable

AVG-1741 linux-lts 5.10.56-1 Medium Vulnerable

https://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf.git/commit/?id=c4eb1f403243fc7bbb7de644db8587c03de36da6