Severity
4.7MEDIUMNVD
OSV6.5
EPSS
0.5%
top 35.26%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 23
Latest updateMay 24

Description

In kernel/bpf/verifier.c in the Linux kernel before 5.12.13, a branch can be mispredicted (e.g., because of type confusion) and consequently an unprivileged BPF program can read arbitrary memory locations via a side-channel attack, aka CID-9183671af6db.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.0 | Impact: 3.6

Affected Packages10 packages

Also affects: Debian Linux 9.0

Patches

🔴Vulnerability Details

9
GHSA
GHSA-w9w3-f8q7-x576: In kernel/bpf/verifier2022-05-24
OSV
linux-oem-5.10 vulnerabilities2021-10-20
OSV
linux-azure, linux-azure-5.11 regression2021-10-18
OSV
linux-azure, linux-azure-5.4 regression2021-10-15
OSV
linux-raspi, linux-raspi-5.4 vulnerabilities2021-09-30

📋Vendor Advisories

9
Ubuntu
Linux kernel (OEM) vulnerabilities2021-10-20
Ubuntu
Linux kernel (Azure) regression2021-10-18
Ubuntu
Linux kernel (Azure) regression2021-10-15
Ubuntu
Linux kernel (Raspberry Pi) vulnerabilities2021-09-30
Ubuntu
Linux kernel vulnerabilities2021-09-29

📄Research Papers

1
arXiv
An Analysis of Speculative Type Confusion Vulnerabilities in the Wild2021-07-02