Related Vulnerabilities: CVE-2021-41864  

prealloc_elems_and_freelist in kernel/bpf/stackmap.c in the Linux kernel through 5.14.9 allows unprivileged users to trigger an eBPF multiplication integer overflow with a resultant out-of-bounds write.

Severity Medium

Remote No

Type Arbitrary code execution

Description

prealloc_elems_and_freelist in kernel/bpf/stackmap.c in the Linux kernel through 5.14.9 allows unprivileged users to trigger an eBPF multiplication integer overflow with a resultant out-of-bounds write.

AVG-1881 linux-hardened 5.14.9.hardened1-1 Medium Vulnerable

AVG-1880 linux-zen 5.14.9.zen2-1 Medium Vulnerable

AVG-1741 linux-lts 5.10.70-1 Medium Vulnerable

AVG-1879 linux 5.14.9.arch4-1 5.14.9.arch4-1 Medium Testing

https://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf.git/commit/?id=30e29a9a2bc6a4888335a6ede968b75cd329657a