CVE-2021-3489

Related Vulnerabilities: CVE-2021-3489  

A flaw was found in the Linux kernel. It was discovered that eBPF RINGBUF bpf_ringbuf_reserve did not check that the allocated size was smaller than the ringbuf size. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Description

A flaw was found in the Linux kernel. It was discovered that eBPF RINGBUF bpf_ringbuf_reserve did not check that the allocated size was smaller than the ringbuf size. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Additional Information

  • Bugzilla 1959559: CVE-2021-3489 kernel: Linux kernel eBPF RINGBUF map oversized allocation
  • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
  • FAQ: Frequently asked questions about CVE-2021-3489