CVE-2021-38300

Related Vulnerabilities: CVE-2021-38300  

A flaw was found in the Linux kernel. The cBPF JIT compiler may produce machine code with incorrect branches. This flaw allows an unprivileged user to craft anomalous machine code, where the control flow is hijacked to execute arbitrary kernel code. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

Description

A flaw was found in the Linux kernel. The cBPF JIT compiler may produce machine code with incorrect branches. This flaw allows an unprivileged user to craft anomalous machine code, where the control flow is hijacked to execute arbitrary kernel code. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

Additional Information

  • Bugzilla 2002750: CVE-2021-38300 kernel: crafting anomalous machine code may lead to arbitrary Kernel code execution
  • CWE-94: Improper Control of Generation of Code ('Code Injection')
  • FAQ: Frequently asked questions about CVE-2021-38300