CVE-2018-25020
published 2021-12-08CVE-2018-25020: The BPF subsystem in the Linux kernel before 4.17 mishandles situations with a long jump over an instruction sequence where inner instructions require…
PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.51%
40.4th percentile
The BPF subsystem in the Linux kernel before 4.17 mishandles situations with a long jump over an instruction sequence where inner instructions require substantial expansions into multiple BPF instructions, leading to an overflow. This affects kernel/bpf/core.c and net/core/filter.c.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.17.3-1 (bookworm) | linux 4.17.3-1 (bookworm) |
| linux | linux_kernel | < 4.17 | 4.17 |
| linux | linux_kernel | >= 0 < 4.17.3-1 | 4.17.3-1 |
| linux | linux_kernel | >= 0 < 4.17.3-1 | 4.17.3-1 |
| linux | linux_kernel | >= 0 < 4.17.3-1 | 4.17.3-1 |
| linux | linux_kernel | >= 0 < 4.17.3-1 | 4.17.3-1 |
| linux | linux_kernel | >= 0 < 4.4.0-218.251 | 4.4.0-218.251 |
| linux | linux_kernel | >= 0 < 4.15.0-166.174 | 4.15.0-166.174 |
| linux | linux_kernel | >= 0 < 5.4.0-92.103 | 5.4.0-92.103 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Kernel Live Patch Security Notice
osv·2022-01-06·CVSS 7.8
CVE-2018-25020 [HIGH] Kernel Live Patch Security Notice
Kernel Live Patch Security Notice
The BPF subsystem in the Linux kernel before 4.17 mishandles
situations with a long jump over an instruction sequence where inner
instructions require substantial expansions into multiple BPF instructions,
leading to an overflow. This affects kernel/bpf/core.c and
net/core/filter.c.(CVE-2018-25020)
Maxim Levitsky discovered that the KVM hypervisor implementation for AMD
processors in the Linux kernel did not properly prevent a guest VM from
enabling AVIC in nested guest VMs. An attacker in a guest VM could use this
to write to portions of the host's physical memory.(CVE-2021-3653)
Nadav Amit discovered that the hugetlb implementation in the Linux kernel
did not perform TLB flushes under certain conditions. A local attacker
could use this to leak or alte
GHSA
GHSA-3p95-f3g8-fcgq: The BPF subsystem in the Linux kernel before 4
ghsa_unreviewed·2021-12-09
CVE-2018-25020 [HIGH] CWE-120 GHSA-3p95-f3g8-fcgq: The BPF subsystem in the Linux kernel before 4
The BPF subsystem in the Linux kernel before 4.17 mishandles situations with a long jump over an instruction sequence where inner instructions require substantial expansions into multiple BPF instructions, leading to an overflow. This affects kernel/bpf/core.c and net/core/filter.c.
OSV
CVE-2018-25020: The BPF subsystem in the Linux kernel before 4
osv·2021-12-08·CVSS 7.8
CVE-2018-25020 [HIGH] CVE-2018-25020: The BPF subsystem in the Linux kernel before 4
The BPF subsystem in the Linux kernel before 4.17 mishandles situations with a long jump over an instruction sequence where inner instructions require substantial expansions into multiple BPF instructions, leading to an overflow. This affects kernel/bpf/core.c and net/core/filter.c.
Ubuntu
Kernel Live Patch Security Notice
vendor_ubuntu·2022-01-06·CVSS 7.8
CVE-2021-33909 [HIGH] Kernel Live Patch Security Notice
Title: Kernel Live Patch Security Notice
Summary: Several security issues were fixed in the kernel.
The BPF subsystem in the Linux kernel before 4.17 mishandles
situations with a long jump over an instruction sequence where inner
instructions require substantial expansions into multiple BPF instructions,
leading to an overflow. This affects kernel/bpf/core.c and
net/core/filter.c.(CVE-2018-25020)
Maxim Levitsky discovered that the KVM hypervisor implementation for AMD
processors in the Linux kernel did not properly prevent a guest VM from
enabling AVIC in nested guest VMs. An attacker in a guest VM could use this
to write to portions of the host's physical memory.(CVE-2021-3653)
Nadav Amit discovered that the hugetlb implementation in the Linux kernel
did not perform TLB flushes under
Red Hat
kernel: long jump over an instruction sequence can lead to overflow in the BPF subsystem
vendor_redhat·2018-05-17·CVSS 7.8
CVE-2018-25020 [HIGH] CWE-120 kernel: long jump over an instruction sequence can lead to overflow in the BPF subsystem
kernel: long jump over an instruction sequence can lead to overflow in the BPF subsystem
The BPF subsystem in the Linux kernel before 4.17 mishandles situations with a long jump over an instruction sequence where inner instructions require substantial expansions into multiple BPF instructions, leading to an overflow. This affects kernel/bpf/core.c and net/core/filter.c.
A buffer overflow flaw in the Linux kernel BPF subsystem was found in the way users run BPF with long jump over an instruction sequence where inner instructions require substantial expansions into multiple BPF instructions. A local user could use this flaw to crash the system or escalate their privileges on the system.
Mitigation: The default Red Hat Enterprise Linux kernel prevents unprivileged users from being able to
Debian
CVE-2018-25020: linux - The BPF subsystem in the Linux kernel before 4.17 mishandles situations with a l...
vendor_debian·2018·CVSS 7.8
CVE-2018-25020 [HIGH] CVE-2018-25020: linux - The BPF subsystem in the Linux kernel before 4.17 mishandles situations with a l...
The BPF subsystem in the Linux kernel before 4.17 mishandles situations with a long jump over an instruction sequence where inner instructions require substantial expansions into multiple BPF instructions, leading to an overflow. This affects kernel/bpf/core.c and net/core/filter.c.
Scope: local
bookworm: resolved (fixed in 4.17.3-1)
bullseye: resolved (fixed in 4.17.3-1)
forky: resolved (fixed in 4.17.3-1)
sid: resolved (fixed in 4.17.3-1)
trixie: resolved (fixed in 4.17.3-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://packetstormsecurity.com/files/165477/Kernel-Live-Patch-Security-Notice-LSN-0083-1.htmlhttps://github.com/torvalds/linux/commit/050fad7c4534c13c8eb1d9c2ba66012e014773cbhttps://security.netapp.com/advisory/ntap-20211229-0005/http://packetstormsecurity.com/files/165477/Kernel-Live-Patch-Security-Notice-LSN-0083-1.htmlhttps://github.com/torvalds/linux/commit/050fad7c4534c13c8eb1d9c2ba66012e014773cbhttps://security.netapp.com/advisory/ntap-20211229-0005/
2021-12-08
Published