CVE-2020-8835
published 2020-04-02CVE-2020-8835: In the Linux kernel 5.5.0 and newer, the bpf verifier (kernel/bpf/verifier.c) did not properly restrict the register bounds for 32-bit operations, leading to…
PriorityP344high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
6.01%
92.5th percentile
In the Linux kernel 5.5.0 and newer, the bpf verifier (kernel/bpf/verifier.c) did not properly restrict the register bounds for 32-bit operations, leading to out-of-bounds reads and writes in kernel memory. The vulnerability also affects the Linux 5.4 stable series, starting with v5.4.7, as the introducing commit was backported to that branch. This vulnerability was fixed in 5.6.1, 5.5.14, and 5.4.29. (issue is aka ZDI-CAN-10780)
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | linux | < linux 5.5.13-2 (bookworm) | linux 5.5.13-2 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| linux | linux_kernel | >= 0 < 5.5.13-2 | 5.5.13-2 |
| linux | linux_kernel | >= 0 < 5.5.13-2 | 5.5.13-2 |
| linux | linux_kernel | >= 0 < 5.5.13-2 | 5.5.13-2 |
| linux | linux_kernel | >= 0 < 5.5.13-2 | 5.5.13-2 |
| linux | linux_kernel | >= 5.4.7 < 5.4.29 | 5.4.29 |
| linux | linux_kernel | >= 5.5.0 < 5.5.14 | 5.5.14 |
| linux | linux_kernel | >= 5.6 < 5.6.1 | 5.6.1 |
| linux_kernel | linux_kernel | >= 5.4.7 < 5.4-stable* | 5.4-stable* |
| linux_kernel | linux_kernel | >= 5.5-stable < 5.5.14 | 5.5.14 |
| linux_kernel | linux_kernel | >= 5.6-stable < 5.6.1 | 5.6.1 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-774r-wvx9-mm68: In the Linux kernel 5
ghsa_unreviewed·2022-05-24
CVE-2020-8835 [HIGH] CWE-119 GHSA-774r-wvx9-mm68: In the Linux kernel 5
In the Linux kernel 5.5.0 and newer, the bpf verifier (kernel/bpf/verifier.c) did not properly restrict the register bounds for 32-bit operations, leading to out-of-bounds reads and writes in kernel memory. The vulnerability also affects the Linux 5.4 stable series, starting with v5.4.7, as the introducing commit was backported to that branch. This vulnerability was fixed in 5.6.1, 5.5.14, and 5.4.29. (issue is aka ZDI-CAN-10780)
OSV
CVE-2020-8835: In the Linux kernel 5
osv·2020-04-02·CVSS 7.8
CVE-2020-8835 [HIGH] CVE-2020-8835: In the Linux kernel 5
In the Linux kernel 5.5.0 and newer, the bpf verifier (kernel/bpf/verifier.c) did not properly restrict the register bounds for 32-bit operations, leading to out-of-bounds reads and writes in kernel memory. The vulnerability also affects the Linux 5.4 stable series, starting with v5.4.7, as the introducing commit was backported to that branch. This vulnerability was fixed in 5.6.1, 5.5.14, and 5.4.29. (issue is aka ZDI-CAN-10780)
Red Hat
kernel: out-of-bounds read/write in the bpf verifier
vendor_redhat·2020-03-30·CVSS 7.8
CVE-2020-8835 [HIGH] CWE-787 kernel: out-of-bounds read/write in the bpf verifier
kernel: out-of-bounds read/write in the bpf verifier
In the Linux kernel 5.5.0 and newer, the bpf verifier (kernel/bpf/verifier.c) did not properly restrict the register bounds for 32-bit operations, leading to out-of-bounds reads and writes in kernel memory. The vulnerability also affects the Linux 5.4 stable series, starting with v5.4.7, as the introducing commit was backported to that branch. This vulnerability was fixed in 5.6.1, 5.5.14, and 5.4.29. (issue is aka ZDI-CAN-10780)
An out-of-bounds access flaw was found in the Linux kernel’s implementation of the eBPF code verifier, where an incorrect register bounds calculation while checking 32-bit instructions in an eBPF program occurs. This flaw allows an unprivileged user or process to execute eBPF programs to crash the kernel, resu
Ubuntu
Linux kernel vulnerability
vendor_ubuntu·2020-03-30
CVE-2020-8835 Linux kernel vulnerability
Title: Linux kernel vulnerability
Summary: The system could be made to expose sensitive information or run
programs as an administrator.
Manfred Paul discovered that the bpf verifier in the Linux kernel did not
properly calculate register bounds for certain operations. A local attacker
could use this to expose sensitive information (kernel memory) or gain
administrative privileges.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-ge
Debian
CVE-2020-8835: linux - In the Linux kernel 5.5.0 and newer, the bpf verifier (kernel/bpf/verifier.c) di...
vendor_debian·2020·CVSS 7.8
CVE-2020-8835 [HIGH] CVE-2020-8835: linux - In the Linux kernel 5.5.0 and newer, the bpf verifier (kernel/bpf/verifier.c) di...
In the Linux kernel 5.5.0 and newer, the bpf verifier (kernel/bpf/verifier.c) did not properly restrict the register bounds for 32-bit operations, leading to out-of-bounds reads and writes in kernel memory. The vulnerability also affects the Linux 5.4 stable series, starting with v5.4.7, as the introducing commit was backported to that branch. This vulnerability was fixed in 5.6.1, 5.5.14, and 5.4.29. (issue is aka ZDI-CAN-10780)
Scope: local
bookworm: resolved (fixed in 5.5.13-2)
bullseye: resolved (fixed in 5.5.13-2)
forky: resolved (fixed in 5.5.13-2)
sid: resolved (fixed in 5.5.13-2)
trixie: resolved (fixed in 5.5.13-2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-8835 kernel: out-of-bounds read/write in the bpf verifier [fedora-all]
bugzilla·2020-03-30·CVSS 7.8
CVE-2020-8835 [HIGH] CVE-2020-8835 kernel: out-of-bounds read/write in the bpf verifier [fedora-all]
CVE-2020-8835 kernel: out-of-bounds read/write in the bpf verifier [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versio
Bugzilla
CVE-2020-8835 kernel: out-of-bounds read/write in the bpf verifier
bugzilla·2020-03-26·CVSS 7.8
CVE-2020-8835 [HIGH] CVE-2020-8835 kernel: out-of-bounds read/write in the bpf verifier
CVE-2020-8835 kernel: out-of-bounds read/write in the bpf verifier
An out-of-bounds access issue was found in the eBPF code verifier implemented in the Linux kernel. It occurs due to incorrect register bounds calculation while checking 32bit instructions in a eBPF program.
An unprivileged user/process able to execute eBPF programs could use this flaw to crash the kernel resulting in DoS or potentially gain root privileges on the system.
Reference:
-> https://www.openwall.com/lists/oss-security/2020/03/30/3
Discussion:
Mitigation:
The Linux kernel versions as shipped with Red Hat Enterprise Linux 5, 6, 7, 8 and Red Hat Enterprise Linux MRG 2 are not affected because they did not backport the commit
581738a681b6 ("bpf: Provide better register bounds after jmp32 instructions")
which i
Bugzilla
CVE-2019-8835 webkitgtk: Processing maliciously crafted web content may lead to arbitrary code execution
bugzilla·2020-03-24·CVSS 8.8
CVE-2019-8835 [HIGH] CVE-2019-8835 webkitgtk: Processing maliciously crafted web content may lead to arbitrary code execution
CVE-2019-8835 webkitgtk: Processing maliciously crafted web content may lead to arbitrary code execution
A flaw was found in WebKitGTK before 2.26.3. Processing maliciously crafted web content may lead to arbitrary code execution.
References:
https://www.openwall.com/lists/oss-security/2020/01/23/2
https://webkitgtk.org/security/WSA-2020-0001.html
Discussion:
Created webkit2gtk3 tracking bugs for this issue:
Affects: fedora-all [bug 1816685]
---
External References:
https://webkitgtk.org/security/WSA-2020-0001.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
ht
arXiv
KernJC: Automated Vulnerable Environment Generation for Linux Kernel Vulnerabilities
arxiv_fulltext·2024-09-24
KernJC: Automated Vulnerable Environment Generation for Linux Kernel Vulnerabilities
: Automated Vulnerable Environment Generation for Linux Kernel Vulnerabilities
Bonan Ruan
National University of Singapore
Jiahao Liu
National University of Singapore
Chuqi Zhang
National University of Singapore
Zhenkai Liang
National University of Singapore
## Abstract
Linux kernel vulnerability reproduction is a critical task in system security.
To reproduce a kernel vulnerability, the vulnerable environment and the Proof of Concept (PoC) program are needed.
Most existing research focuses on the generation of PoC, while the construction of environment is overlooked.
However, establishing an effective vulnerable environment to trigger a vulnerability is challenging.
Firstly, it is hard to guarantee that the selected kernel version for reproduction is vulnerable, as the vulner
CTF
bpf_badjmp / README
ctf_writeups·2021·CVSS 5.5
CVE-2016-2383 [MEDIUM] bpf_badjmp / README
# UIUCTF 2021: ebpf_badjmp solution
Decription:
>We recreated CVE-2016-2383. Your task is to read out the variable named `uiuctf_flag` in the kernel memory, by building an arbitrary kernel memory read via a malicious eBPF program. Use of provided starter code is optional; if you have better methods feel free to use them instead.
>
>`$ stty raw -echo; nc bpf-badjmp.chal.uiuc.tf 1337; stty -raw echo`
>
>Upload large files to VM: `$ nc bpf-badjmp.chal.uiuc.tf 1338
>HINT: How do you create a backwards jump without introducing unreachable code or creating loops?
## The Vulnerability
Here we're given the patch which will introduce bug in eBPF kernel subsystem.
``` diff
diff --git a/kernel/bpf/core.c b/kernel/bpf/core.c
index 75244ecb2389..277f0e475181 100644
--- a/kernel/bpf/core.c
+++ b/kerne
CTF
20200928-tokyowesternsctf2020 / README
ctf_writeups·2020
20200928-tokyowesternsctf2020 / README
# TokyoWesterns CTF 6th 2020
**It's recommended to read our responsive [web version](https://balsn.tw/ctf_writeup/20200928-tokyowesternsctf2020/) of this writeup.**
- [TokyoWesterns CTF 6th 2020](#tokyowesterns-ctf-6th-2020)
- [Misc](#misc)
- [Birds](#birds)
- [Web](#web)
- [urlcheck_v1](#urlcheck_v1)
- [urlcheck_v2](#urlcheck_v2)
- [Angular of the Universe](#angular-of-the-universe)
- [Angular of the Universe (flag 2)](#angular-of-the-universe-flag-2)
- [bfnote (not-solved)](#bfnote-not-solved)
- [Pwn](#pwn)
- [Extended Extended Berkeley Packet Filter](#extended-extended-berkeley-packet-filter)
- [IL](#il)
- [smash](#smash)
- [nothing more to say 2020](#nothing-more-to-say-2020)
- [Blind Shot](#blind-shot)
- [Online Nonogram](#online-nonogram)
- [Crypto](#crypto)
- [easy-hash](#easy-ha
http://www.openwall.com/lists/oss-security/2021/07/20/1https://git.kernel.org/pub/scm/linux/kernel/git/netdev/net-next.git/commit/?id=f2d67fec0b43edce8c416101cdc52e71145b5fefhttps://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=f2d67fec0b43edce8c416101cdc52e71145b5fefhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F7OONYGMSYBEFHLHZJK3GOI5Z553G4LD/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TF4PQZBEPNXDSK5DOBMW54OCLP25FTCD/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YXBWSHZ6DJIZVXKXGZPK6QPFCY7VKZEG/https://lore.kernel.org/bpf/20200330160324.15259-1-daniel%40iogearbox.net/T/https://security.netapp.com/advisory/ntap-20200430-0004/https://usn.ubuntu.com/4313-1/https://usn.ubuntu.com/usn/usn-4313-1https://www.openwall.com/lists/oss-security/2020/03/30/3https://www.thezdi.com/blog/2020/3/19/pwn2own-2020-day-one-resultshttp://www.openwall.com/lists/oss-security/2021/07/20/1https://git.kernel.org/pub/scm/linux/kernel/git/netdev/net-next.git/commit/?id=f2d67fec0b43edce8c416101cdc52e71145b5fefhttps://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=f2d67fec0b43edce8c416101cdc52e71145b5fefhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F7OONYGMSYBEFHLHZJK3GOI5Z553G4LD/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TF4PQZBEPNXDSK5DOBMW54OCLP25FTCD/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YXBWSHZ6DJIZVXKXGZPK6QPFCY7VKZEG/https://lore.kernel.org/bpf/20200330160324.15259-1-daniel%40iogearbox.net/T/https://security.netapp.com/advisory/ntap-20200430-0004/https://usn.ubuntu.com/4313-1/https://usn.ubuntu.com/usn/usn-4313-1https://www.openwall.com/lists/oss-security/2020/03/30/3https://www.thezdi.com/blog/2020/3/19/pwn2own-2020-day-one-results
2020-04-02
Published