CVE-2021-45402

Related Vulnerabilities: CVE-2021-45402  

The check_alu_op() function in kernel/bpf/verifier.c in the Linux kernel through v5.16-rc5 did not properly update bounds while handling the mov32 instruction, which allows local users to obtain potentially sensitive address information, aka a "pointer leak."

Description

The MITRE CVE dictionary describes this issue as:

The check_alu_op() function in kernel/bpf/verifier.c in the Linux kernel through v5.16-rc5 did not properly update bounds while handling the mov32 instruction, which allows local users to obtain potentially sensitive address information, aka a "pointer leak."

Additional Information

  • Bugzilla 2054865: CVE-2021-45402 kernel: pointer leak in check_alu_op() of kernel/bpf/verifier.c
  • FAQ: Frequently asked questions about CVE-2021-45402