Severity
3.3LOWNVD
OSV6.7
EPSS
0.1%
top 75.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 28
Latest updateFeb 14

Description

A flaw was found in the Linux kernel in versions before 5.4.92 in the BPF protocol. This flaw allows an attacker with a local account to leak information about kernel internal addresses. The highest threat from this vulnerability is to confidentiality.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 1.8 | Impact: 1.4

Affected Packages6 packages

NVDlinux/linux_kernel< 5.4.92
Debianlinux/linux_kernel< 5.10.4-1+3
Ubuntulinux/linux_kernel< 5.4.0-67.75
CVEListV5linux/linux_kernelkernel 5.4.92
debiandebian/linux< linux 5.10.4-1 (bookworm)

Also affects: Enterprise Linux 5.0, 6.0, 8.0, Fedora 33

🔴Vulnerability Details

4
GHSA
GHSA-r3jm-2397-mvmw: A flaw was found in the Linux kernel in versions before 52022-05-24
OSV
CVE-2021-20239: A flaw was found in the Linux kernel in versions before 52021-05-28
OSV
linux, linux-aws, linux-azure, linux-gcp, linux-hwe-5.8, linux-kvm, linux-oracle, linux-raspi vulnerabilities2021-04-13
OSV
linux, linux-aws, linux-aws-5.4, linux-azure, linux-azure-5.4, linux-gcp, linux-gcp-5.4, linux-gke-5.4, linux-gkeop, linux-gkeop-5.4, linux-hwe-5.4, linux-kvm, linux-oracle, linux-oracle-5.4, linux-ra2021-03-16

📋Vendor Advisories

5
Palo Alto
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS2024-02-14
Ubuntu
Linux kernel vulnerabilities2021-04-13
Ubuntu
Linux kernel vulnerabilities2021-03-16
Red Hat
kernel: setsockopt System Call Untrusted Pointer Dereference Information Disclosure2021-02-01
Debian
CVE-2021-20239: linux - A flaw was found in the Linux kernel in versions before 5.4.92 in the BPF protoc...2021
CVE-2021-20239 — Untrusted Pointer Dereference | cvebase