CVE-2021-33624
published 2021-06-23CVE-2021-33624: In kernel/bpf/verifier.c in the Linux kernel before 5.12.13, a branch can be mispredicted (e.g., because of type confusion) and consequently an unprivileged…
PriorityP423medium4.7CVSS 3.1
AVLACHPRLUINSUCHINAN
EPSS
0.92%
56.9th percentile
In kernel/bpf/verifier.c in the Linux kernel before 5.12.13, a branch can be mispredicted (e.g., because of type confusion) and consequently an unprivileged BPF program can read arbitrary memory locations via a side-channel attack, aka CID-9183671af6db.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | linux | < linux 5.10.46-1 (bookworm) | linux 5.10.46-1 (bookworm) |
| linux | linux_kernel | < 5.12.13 | 5.12.13 |
| linux | linux_kernel | >= 0 < 5.10.46-1 | 5.10.46-1 |
| linux | linux_kernel | >= 0 < 5.10.46-1 | 5.10.46-1 |
| linux | linux_kernel | >= 0 < 5.10.46-1 | 5.10.46-1 |
| linux | linux_kernel | >= 0 < 5.10.46-1 | 5.10.46-1 |
| linux | linux_kernel | >= 0 < 5.4.0-88.99 | 5.4.0-88.99 |
| msrc | cbl2_kernel_5.10.78.1-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| msrc | cm1_kernel_5.10.60.1-1_on_cbl_mariner_1.0 | — | — |
CVSS provenance
nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.7MEDIUMAV:L/AC:M/Au:N/C:C/I:N/A:N
osv6.5MEDIUM
vendor_ubuntu6.5MEDIUM
vendor_debian4.7MEDIUM
vendor_msrc4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (OEM) vulnerabilities
vendor_ubuntu·2021-10-20·CVSS 6.5
CVE-2021-3679 [MEDIUM] Linux kernel (OEM) vulnerabilities
Title: Linux kernel (OEM) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that a race condition existed in the Atheros Ath9k WiFi
driver in the Linux kernel. An attacker could possibly use this to expose
sensitive information (WiFi network traffic). (CVE-2020-3702)
Ofek Kirzner, Adam Morrison, Benedict Schlueter, and Piotr Krysiuk
discovered that the BPF verifier in the Linux kernel missed possible
mispredicted branches due to type confusion, allowing a side-channel
attack. An attacker could use this to expose sensitive information.
(CVE-2021-33624)
Benedict Schlueter discovered that the BPF subsystem in the Linux kernel
did not properly protect against Speculative Store Bypass (SSB) side-
channel attacks in some situations. A local at
Ubuntu
Linux kernel (Azure) regression
vendor_ubuntu·2021-10-18·CVSS 4.7
[MEDIUM] Linux kernel (Azure) regression
Title: Linux kernel (Azure) regression
Summary: USN-5092-2 introduced a regression in the Linux kernel for Microsoft
Azure cloud systems.
USN-5092-2 fixed vulnerabilities in Linux 5.11-based kernels.
Unfortunately, for Linux kernels intended for use within Microsoft
Azure environments, that update introduced a regression that could
cause the kernel to fail to boot in large Azure instance types.
This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Valentina Palmiotti discovered that the io_uring subsystem in the Linux
kernel could be coerced to free adjacent memory. A local attacker could use
this to execute arbitrary code. (CVE-2021-41073)
Ofek Kirzner, Adam Morrison, Benedict Schlueter, and Piotr Krysiuk
discovered that the BPF verifier in th
Ubuntu
Linux kernel (Azure) regression
vendor_ubuntu·2021-10-15·CVSS 4.7
[MEDIUM] Linux kernel (Azure) regression
Title: Linux kernel (Azure) regression
Summary: USN-5091-1 introduced a regression in the Linux kernel for Microsoft
Azure cloud systems.
USN-5091-1 fixed vulnerabilities in Linux 5.4-based kernels.
Unfortunately, for Linux kernels intended for use within Microsoft
Azure environments, that update introduced a regression that could
cause the kernel to fail to boot in large Azure instance types.
This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Ofek Kirzner, Adam Morrison, Benedict Schlueter, and Piotr Krysiuk
discovered that the BPF verifier in the Linux kernel missed possible
mispredicted branches due to type confusion, allowing a side-channel
attack. An attacker could use this to expose sensitive information.
(CVE-2021-33624)
It was discov
Ubuntu
Linux kernel (Raspberry Pi) vulnerabilities
vendor_ubuntu·2021-09-30·CVSS 4.7
CVE-2021-3679 [MEDIUM] Linux kernel (Raspberry Pi) vulnerabilities
Title: Linux kernel (Raspberry Pi) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Ofek Kirzner, Adam Morrison, Benedict Schlueter, and Piotr Krysiuk
discovered that the BPF verifier in the Linux kernel missed possible
mispredicted branches due to type confusion, allowing a side-channel
attack. An attacker could use this to expose sensitive information.
(CVE-2021-33624)
It was discovered that the tracing subsystem in the Linux kernel did not
properly keep track of per-cpu ring buffer state. A privileged attacker
could use this to cause a denial of service. (CVE-2021-3679)
It was discovered that the Virtio console implementation in the Linux
kernel did not properly validate input lengths in some situations. A local
attacker could possibly use this to cau
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2021-09-29·CVSS 4.7
CVE-2021-41073 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Valentina Palmiotti discovered that the io_uring subsystem in the Linux
kernel could be coerced to free adjacent memory. A local attacker could use
this to execute arbitrary code. (CVE-2021-41073)
Ofek Kirzner, Adam Morrison, Benedict Schlueter, and Piotr Krysiuk
discovered that the BPF verifier in the Linux kernel missed possible
mispredicted branches due to type confusion, allowing a side-channel
attack. An attacker could use this to expose sensitive information.
(CVE-2021-33624)
Benedict Schlueter discovered that the BPF subsystem in the Linux kernel
did not properly protect against Speculative Store Bypass (SSB) side-
channel attacks in some situations. A local attacker could possib
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2021-09-28·CVSS 4.7
CVE-2021-38160 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Ofek Kirzner, Adam Morrison, Benedict Schlueter, and Piotr Krysiuk
discovered that the BPF verifier in the Linux kernel missed possible
mispredicted branches due to type confusion, allowing a side-channel
attack. An attacker could use this to expose sensitive information.
(CVE-2021-33624)
It was discovered that the tracing subsystem in the Linux kernel did not
properly keep track of per-cpu ring buffer state. A privileged attacker
could use this to cause a denial of service. (CVE-2021-3679)
Alexey Kardashevskiy discovered that the KVM implementation for PowerPC
systems in the Linux kernel did not properly validate RTAS arguments in
some situations. An attacker in a guest vm could use th
Red Hat
kernel: Linux kernel BPF protection against speculative execution attacks can be bypassed to read arbitrary kernel memory
vendor_redhat·2021-06-21·CVSS 4.7
CVE-2021-33624 [MEDIUM] CWE-119 kernel: Linux kernel BPF protection against speculative execution attacks can be bypassed to read arbitrary kernel memory
kernel: Linux kernel BPF protection against speculative execution attacks can be bypassed to read arbitrary kernel memory
In kernel/bpf/verifier.c in the Linux kernel before 5.12.13, a branch can be mispredicted (e.g., because of type confusion) and consequently an unprivileged BPF program can read arbitrary memory locations via a side-channel attack, aka CID-9183671af6db.
A flaw was found in the Linux kernel's BPF subsystem, where protection against speculative execution attacks (Spectre mitigation) can be bypassed. The highest threat from this vulnerability is to confidentiality.
Mitigation: The default Red Hat Enterprise Linux kernel setting prevents unprivileged users from being able to use eBPF via the kernel.unprivileged_bpf_disabled sysctl. As such, exploiting this issue would re
Microsoft
In kernel/bpf/verifier.c in the Linux kernel before 5.12.13 a branch can be mispredicted (e.g. because of type confusion) and consequently an unprivileged BPF program can read arbitrary memory locatio
vendor_msrc·2021-06-08·CVSS 4.7
CVE-2021-33624 [MEDIUM] CWE-843 In kernel/bpf/verifier.c in the Linux kernel before 5.12.13 a branch can be mispredicted (e.g. because of type confusion) and consequently an unprivileged BPF program can read arbitrary memory locatio
In kernel/bpf/verifier.c in the Linux kernel before 5.12.13 a branch can be mispredicted (e.g. because of type confusion) and consequently an unprivileged BPF program can read arbitrary memory locations via a side-channel attack aka CID-9183671af6db.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to add
Debian
CVE-2021-33624: linux - In kernel/bpf/verifier.c in the Linux kernel before 5.12.13, a branch can be mis...
vendor_debian·2021·CVSS 4.7
CVE-2021-33624 [MEDIUM] CVE-2021-33624: linux - In kernel/bpf/verifier.c in the Linux kernel before 5.12.13, a branch can be mis...
In kernel/bpf/verifier.c in the Linux kernel before 5.12.13, a branch can be mispredicted (e.g., because of type confusion) and consequently an unprivileged BPF program can read arbitrary memory locations via a side-channel attack, aka CID-9183671af6db.
Scope: local
bookworm: resolved (fixed in 5.10.46-1)
bullseye: resolved (fixed in 5.10.46-1)
forky: resolved (fixed in 5.10.46-1)
sid: resolved (fixed in 5.10.46-1)
trixie: resolved (fixed in 5.10.46-1)
GHSA
GHSA-w9w3-f8q7-x576: In kernel/bpf/verifier
ghsa_unreviewed·2022-05-24
CVE-2021-33624 [MEDIUM] CWE-203 GHSA-w9w3-f8q7-x576: In kernel/bpf/verifier
In kernel/bpf/verifier.c in the Linux kernel before 5.12.13, a branch can be mispredicted (e.g., because of type confusion) and consequently an unprivileged BPF program can read arbitrary memory locations via a side-channel attack, aka CID-9183671af6db.
OSV
linux-oem-5.10 vulnerabilities
osv·2021-10-20·CVSS 6.5
CVE-2020-3702 [MEDIUM] linux-oem-5.10 vulnerabilities
linux-oem-5.10 vulnerabilities
It was discovered that a race condition existed in the Atheros Ath9k WiFi
driver in the Linux kernel. An attacker could possibly use this to expose
sensitive information (WiFi network traffic). (CVE-2020-3702)
Ofek Kirzner, Adam Morrison, Benedict Schlueter, and Piotr Krysiuk
discovered that the BPF verifier in the Linux kernel missed possible
mispredicted branches due to type confusion, allowing a side-channel
attack. An attacker could use this to expose sensitive information.
(CVE-2021-33624)
Benedict Schlueter discovered that the BPF subsystem in the Linux kernel
did not properly protect against Speculative Store Bypass (SSB) side-
channel attacks in some situations. A local attacker could possibly use
this to expose sensitive information. (CVE-2021-345
OSV
linux-azure, linux-azure-5.11 regression
osv·2021-10-18·CVSS 4.7
[MEDIUM] linux-azure, linux-azure-5.11 regression
linux-azure, linux-azure-5.11 regression
USN-5092-2 fixed vulnerabilities in Linux 5.11-based kernels.
Unfortunately, for Linux kernels intended for use within Microsoft
Azure environments, that update introduced a regression that could
cause the kernel to fail to boot in large Azure instance types.
This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Valentina Palmiotti discovered that the io_uring subsystem in the Linux
kernel could be coerced to free adjacent memory. A local attacker could use
this to execute arbitrary code. (CVE-2021-41073)
Ofek Kirzner, Adam Morrison, Benedict Schlueter, and Piotr Krysiuk
discovered that the BPF verifier in the Linux kernel missed possible
mispredicted branches due to type confusion, allowing a side-channe
OSV
linux-azure, linux-azure-5.4 regression
osv·2021-10-15·CVSS 4.7
[MEDIUM] linux-azure, linux-azure-5.4 regression
linux-azure, linux-azure-5.4 regression
USN-5091-1 fixed vulnerabilities in Linux 5.4-based kernels.
Unfortunately, for Linux kernels intended for use within Microsoft
Azure environments, that update introduced a regression that could
cause the kernel to fail to boot in large Azure instance types.
This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Ofek Kirzner, Adam Morrison, Benedict Schlueter, and Piotr Krysiuk
discovered that the BPF verifier in the Linux kernel missed possible
mispredicted branches due to type confusion, allowing a side-channel
attack. An attacker could use this to expose sensitive information.
(CVE-2021-33624)
It was discovered that the tracing subsystem in the Linux kernel did not
properly keep track of per-cpu ring buf
OSV
linux-raspi, linux-raspi-5.4 vulnerabilities
osv·2021-09-30·CVSS 4.7
CVE-2021-33624 [MEDIUM] linux-raspi, linux-raspi-5.4 vulnerabilities
linux-raspi, linux-raspi-5.4 vulnerabilities
Ofek Kirzner, Adam Morrison, Benedict Schlueter, and Piotr Krysiuk
discovered that the BPF verifier in the Linux kernel missed possible
mispredicted branches due to type confusion, allowing a side-channel
attack. An attacker could use this to expose sensitive information.
(CVE-2021-33624)
It was discovered that the tracing subsystem in the Linux kernel did not
properly keep track of per-cpu ring buffer state. A privileged attacker
could use this to cause a denial of service. (CVE-2021-3679)
It was discovered that the Virtio console implementation in the Linux
kernel did not properly validate input lengths in some situations. A local
attacker could possibly use this to cause a denial of service (system
crash). (CVE-2021-38160)
Michael Wakabay
OSV
linux-hwe-5.11, linux-azure, linux-azure-5.11, linux-oracle-5.11 vulnerabilities
osv·2021-09-29·CVSS 4.7
CVE-2021-41073 [MEDIUM] linux-hwe-5.11, linux-azure, linux-azure-5.11, linux-oracle-5.11 vulnerabilities
linux-hwe-5.11, linux-azure, linux-azure-5.11, linux-oracle-5.11 vulnerabilities
Valentina Palmiotti discovered that the io_uring subsystem in the Linux
kernel could be coerced to free adjacent memory. A local attacker could use
this to execute arbitrary code. (CVE-2021-41073)
Ofek Kirzner, Adam Morrison, Benedict Schlueter, and Piotr Krysiuk
discovered that the BPF verifier in the Linux kernel missed possible
mispredicted branches due to type confusion, allowing a side-channel
attack. An attacker could use this to expose sensitive information.
(CVE-2021-33624)
Benedict Schlueter discovered that the BPF subsystem in the Linux kernel
did not properly protect against Speculative Store Bypass (SSB) side-
channel attacks in some situations. A local attacker could possibly use
this to expose
OSV
linux, linux-aws, linux-aws-5.4, linux-azure, linux-azure-5.4, linux-gcp, linux-gcp-5.4, linux-gke, linux-gke-5.4, linux-gkeop, linux-gkeop-5.4, linux-hwe-5.4, linux-kvm, linux-oracle, linux-oracle-5.
osv·2021-09-28·CVSS 4.7
[MEDIUM] linux, linux-aws, linux-aws-5.4, linux-azure, linux-azure-5.4, linux-gcp, linux-gcp-5.4, linux-gke, linux-gke-5.4, linux-gkeop, linux-gkeop-5.4, linux-hwe-5.4, linux-kvm, linux-oracle, linux-oracle-5.
linux, linux-aws, linux-aws-5.4, linux-azure, linux-azure-5.4, linux-gcp, linux-gcp-5.4, linux-gke, linux-gke-5.4, linux-gkeop, linux-gkeop-5.4, linux-hwe-5.4, linux-kvm, linux-oracle, linux-oracle-5.4 vulnerabilities
Ofek Kirzner, Adam Morrison, Benedict Schlueter, and Piotr Krysiuk
discovered that the BPF verifier in the Linux kernel missed possible
mispredicted branches due to type confusion, allowing a side-channel
attack. An attacker could use this to expose sensitive information.
(CVE-2021-33624)
It was discovered that the tracing subsystem in the Linux kernel did not
properly keep track of per-cpu ring buffer state. A privileged attacker
could use this to cause a denial of service. (CVE-2021-3679)
Alexey Kardashevskiy discovered that the KVM implementation for PowerPC
systems in
OSV
linux, linux-aws, linux-aws-5.11, linux-gcp, linux-kvm, linux-oracle, linux-raspi vulnerabilities
osv·2021-09-28·CVSS 4.7
CVE-2021-41073 [MEDIUM] linux, linux-aws, linux-aws-5.11, linux-gcp, linux-kvm, linux-oracle, linux-raspi vulnerabilities
linux, linux-aws, linux-aws-5.11, linux-gcp, linux-kvm, linux-oracle, linux-raspi vulnerabilities
Valentina Palmiotti discovered that the io_uring subsystem in the Linux
kernel could be coerced to free adjacent memory. A local attacker could use
this to execute arbitrary code. (CVE-2021-41073)
Ofek Kirzner, Adam Morrison, Benedict Schlueter, and Piotr Krysiuk
discovered that the BPF verifier in the Linux kernel missed possible
mispredicted branches due to type confusion, allowing a side-channel
attack. An attacker could use this to expose sensitive information.
(CVE-2021-33624)
Benedict Schlueter discovered that the BPF subsystem in the Linux kernel
did not properly protect against Speculative Store Bypass (SSB) side-
channel attacks in some situations. A local attacker could possibly u
OSV
CVE-2021-33624: In kernel/bpf/verifier
osv·2021-06-23·CVSS 4.7
CVE-2021-33624 [MEDIUM] CVE-2021-33624: In kernel/bpf/verifier
In kernel/bpf/verifier.c in the Linux kernel before 5.12.13, a branch can be mispredicted (e.g., because of type confusion) and consequently an unprivileged BPF program can read arbitrary memory locations via a side-channel attack, aka CID-9183671af6db.
No detection rules found.
No public exploits indexed.
arXiv
An Analysis of Speculative Type Confusion Vulnerabilities in the Wild
arxiv_fulltext·2021-07-02
An Analysis of Speculative Type Confusion Vulnerabilities in the Wild
An Analysis of Speculative Type Confusion Vulnerabilities in the Wild
Ofek Kirzner Adam Morrison
Tel Aviv University
empty
## Abstract
Spectre v1 attacks, which exploit conditional branch misprediction, are often identified
with attacks that bypass array bounds checking to leak data from a victim's memory.
Generally, however, Spectre v1 attacks can exploit any conditional branch misprediction that
makes the victim execute code incorrectly. In this paper, we investigate
speculative type confusion, a Spectre v1 attack vector in which branch mispredictions
make the victim execute with variables holding values of the wrong type and thereby leak memory content.
We observe that speculative type confusion can be inadvertently introduced by a compiler,
making it extremely hard for programmer
Bugzilla
CVE-2021-33624 kernel: Linux kernel BPF protection against speculative execution attacks can be bypassed to read arbitrary kernel memory
bugzilla·2021-06-21·CVSS 4.7
CVE-2021-33624 [MEDIUM] CVE-2021-33624 kernel: Linux kernel BPF protection against speculative execution attacks can be bypassed to read arbitrary kernel memory
CVE-2021-33624 kernel: Linux kernel BPF protection against speculative execution attacks can be bypassed to read arbitrary kernel memory
A flaw was found in the Linux kernel's BPF subsystem in sanitize_ptr_alu in kernel/bpf/verifier.c, where protection against speculative execution attacks (Spectre mitigation) can be bypassed. The highest threat from this vulnerability is to confidentiality.
References:
https://www.openwall.com/lists/oss-security/2021/06/21/1
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1974457]
http://www.openwall.com/lists/oss-security/2021/06/21/1https://github.com/benschlueter/CVE-2021-33624https://github.com/torvalds/linux/commit/9183671af6dbf60a1219371d4ed73e23f43b49dbhttps://lists.debian.org/debian-lts-announce/2021/10/msg00010.htmlhttps://www.usenix.org/conference/usenixsecurity21/presentation/kirznerhttp://www.openwall.com/lists/oss-security/2021/06/21/1https://github.com/torvalds/linux/commit/9183671af6dbf60a1219371d4ed73e23f43b49dbhttps://lists.debian.org/debian-lts-announce/2021/10/msg00010.htmlhttps://www.usenix.org/conference/usenixsecurity21/presentation/kirzner
2021-06-23
Published