CVE-2021-3444
published 2021-03-23CVE-2021-3444: The bpf verifier in the Linux kernel did not properly handle mod32 destination register truncation when the source register was known to be 0. A local attacker…
PriorityP341high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.61%
45.2th percentile
The bpf verifier in the Linux kernel did not properly handle mod32 destination register truncation when the source register was known to be 0. A local attacker with the ability to load bpf programs could use this gain out-of-bounds reads in kernel memory leading to information disclosure (kernel memory), and possibly out-of-bounds writes that could potentially lead to code execution. This issue was addressed in the upstream kernel in commit 9b00f1b78809 ("bpf: Fix truncation handling for mod32 dst reg wrt zero") and in Linux stable kernels 5.11.2, 5.10.19, and 5.4.101.
Affected
38 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | linux | < linux 5.10.19-1 (bookworm) | linux 5.10.19-1 (bookworm) |
| chrome_chrome | — | — | |
| linux | kernel | >= 5.10 < 5.10.19 | 5.10.19 |
| linux | kernel | >= 5.11 < 5.11.2 | 5.11.2 |
| linux | kernel | >= 5.4 < 5.4.101 | 5.4.101 |
| linux | kernel | >= trunk < 5.12-rc1 | 5.12-rc1 |
| linux | linux_kernel | < 5.4.101 | 5.4.101 |
| linux | linux_kernel | >= 0 < 5.10.19-1 | 5.10.19-1 |
| linux | linux_kernel | >= 0 < 5.10.19-1 | 5.10.19-1 |
| linux | linux_kernel | >= 0 < 5.10.19-1 | 5.10.19-1 |
| linux | linux_kernel | >= 0 < 5.10.19-1 | 5.10.19-1 |
| linux | linux_kernel | >= 0 < 5.4.0-70.78 | 5.4.0-70.78 |
| linux | linux_kernel | >= 0 < 4.4.0-203.235 | 4.4.0-203.235 |
| linux | linux_kernel | >= 0 < 4.15.0-136.140 | 4.15.0-136.140 |
| linux | linux_kernel | >= 0 < 5.4.0-70.78 | 5.4.0-70.78 |
| linux | linux_kernel | >= 5.11 < 5.11.2 | 5.11.2 |
| linux | linux_kernel | >= 5.5.0 < 5.10.19 | 5.10.19 |
| msrc | kernel-5.10.57.1-1.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm | — | — |
| msrc | kernel-5.10.57.1-1.cm1.x86_64.rpm_on_cbl_mariner_1.0_x64 | — | — |
| msrc | kernel-debuginfo-5.10.57.1-1.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Chrome
Stable Channel Update for Desktop: CVE-2022-3443
vendor_chrome·2022-09-27·CVSS 4.3
CVE-2022-3443 [LOW] Stable Channel Update for Desktop: CVE-2022-3443
Stable Channel Update for Desktop
CVE-2022-3443: Insufficient data validation in File System API. Reported by Maciej Pulikowski and Konrad Chrząszcz on 2021-08-27 [$1000][ 1208439 ] Low CVE-2022-3444: Insufficient data validation in File System API
Reported by Archie Midha & Vallari Sharma on 2021-05-12 [$ 500][ 1349493 ] Low CVE-2022-4911: Insufficient data validation in DevTools
Severity: low
Ubuntu
Kernel Live Patch Security Notice
vendor_ubuntu·2021-11-11·CVSS 4.4
CVE-2020-29660 [MEDIUM] Kernel Live Patch Security Notice
Title: Kernel Live Patch Security Notice
Summary: Several security issues were fixed in the kernel.
Jann Horn discovered that the tty subsystem of the Linux kernel did not use
consistent locking in some situations, leading to a read-after-free
vulnerability. A local attacker could use this to cause a denial of service
(system crash) or possibly expose sensitive information (kernel memory).(CVE-2020-29660)
Jann Horn discovered a race condition in the tty subsystem of the Linux
kernel in the locking for the TIOCSPGRP ioctl(), leading to a use-after-
free vulnerability. A local attacker could use this to cause a denial of
service (system crash) or possibly execute arbitrary code.(CVE-2020-29661)
De4dCr0w of 360 Alpha Lab discovered that the BPF verifier in the Linux
kernel did not properl
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2021-03-23·CVSS 4.7
CVE-2020-27170 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
De4dCr0w of 360 Alpha Lab discovered that the BPF verifier in the Linux
kernel did not properly handle mod32 destination register truncation when
the source register was known to be 0. A local attacker could use this to
expose sensitive information (kernel memory) or possibly execute arbitrary
code. (CVE-2021-3444)
Adam Nichols discovered that heap overflows existed in the iSCSI subsystem
in the Linux kernel. A local attacker could use this to cause a denial of
service (system crash) or possibly execute arbitrary code. (CVE-2021-27365)
Piotr Krysiuk discovered that the BPF subsystem in the Linux kernel did not
properly compute a speculative execution limit on pointer arithmetic in
some
Microsoft
Linux kernel bpf verifier incorrect mod32 truncation
vendor_msrc·2021-03-09·CVSS 7.8
CVE-2021-3444 [HIGH] CWE-125 Linux kernel bpf verifier incorrect mod32 truncation
Linux kernel bpf verifier incorrect mod32 truncation
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
canonical: canonical
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://
Red Hat
kernel: bpf verifier incorrect mod32 truncation
vendor_redhat·2021-02-13·CVSS 7.8
CVE-2021-3444 [HIGH] CWE-125 kernel: bpf verifier incorrect mod32 truncation
kernel: bpf verifier incorrect mod32 truncation
The bpf verifier in the Linux kernel did not properly handle mod32 destination register truncation when the source register was known to be 0. A local attacker with the ability to load bpf programs could use this gain out-of-bounds reads in kernel memory leading to information disclosure (kernel memory), and possibly out-of-bounds writes that could potentially lead to code execution. This issue was addressed in the upstream kernel in commit 9b00f1b78809 ("bpf: Fix truncation handling for mod32 dst reg wrt zero") and in Linux stable kernels 5.11.2, 5.10.19, and 5.4.101.
An out-of-bounds access flaw was found in the Linux kernel's implementation of the eBPF code verifier in the way a user running the eBPF script uses mod32 destination registe
Debian
CVE-2021-3444: linux - The bpf verifier in the Linux kernel did not properly handle mod32 destination r...
vendor_debian·2021·CVSS 7.8
CVE-2021-3444 [HIGH] CVE-2021-3444: linux - The bpf verifier in the Linux kernel did not properly handle mod32 destination r...
The bpf verifier in the Linux kernel did not properly handle mod32 destination register truncation when the source register was known to be 0. A local attacker with the ability to load bpf programs could use this gain out-of-bounds reads in kernel memory leading to information disclosure (kernel memory), and possibly out-of-bounds writes that could potentially lead to code execution. This issue was addressed in the upstream kernel in commit 9b00f1b78809 ("bpf: Fix truncation handling for mod32 dst reg wrt zero") and in Linux stable kernels 5.11.2, 5.10.19, and 5.4.101.
Scope: local
bookworm: resolved (fixed in 5.10.19-1)
bullseye: resolved (fixed in 5.10.19-1)
forky: resolved (fixed in 5.10.19-1)
sid: resolved (fixed in 5.10.19-1)
trixie: resolved (fixed in 5.10.19-1)
GHSA
GHSA-c55x-85rg-x529: The bpf verifier in the Linux kernel did not properly handle mod32 destination register truncation when the source register was known to be 0
ghsa_unreviewed·2022-05-24
CVE-2021-3444 [HIGH] CWE-125 GHSA-c55x-85rg-x529: The bpf verifier in the Linux kernel did not properly handle mod32 destination register truncation when the source register was known to be 0
The bpf verifier in the Linux kernel did not properly handle mod32 destination register truncation when the source register was known to be 0. A local attacker with the ability to load bpf programs could use this gain out-of-bounds reads in kernel memory leading to information disclosure (kernel memory), and possibly out-of-bounds writes that could potentially lead to code execution. This issue was addressed in the upstream kernel in commit 9b00f1b78809 ("bpf: Fix truncation handling for mod32 dst reg wrt zero") and in Linux stable kernels 5.11.2, 5.10.19, and 5.4.101.
OSV
Kernel Live Patch Security Notice
osv·2021-11-11·CVSS 4.4
CVE-2020-29660 [MEDIUM] Kernel Live Patch Security Notice
Kernel Live Patch Security Notice
Jann Horn discovered that the tty subsystem of the Linux kernel did not use
consistent locking in some situations, leading to a read-after-free
vulnerability. A local attacker could use this to cause a denial of service
(system crash) or possibly expose sensitive information (kernel memory).(CVE-2020-29660)
Jann Horn discovered a race condition in the tty subsystem of the Linux
kernel in the locking for the TIOCSPGRP ioctl(), leading to a use-after-
free vulnerability. A local attacker could use this to cause a denial of
service (system crash) or possibly execute arbitrary code.(CVE-2020-29661)
De4dCr0w of 360 Alpha Lab discovered that the BPF verifier in the Linux
kernel did not properly handle mod32 destination register truncation when
the source regi
OSV
linux, linux-aws, linux-aws-5.4, linux-azure, linux-azure-5.4, linux-gcp, linux-gcp-5.4, linux-gke-5.3, linux-gke-5.4, linux-gkeop, linux-gkeop-5.4, linux-hwe, linux-hwe-5.4, linux-hwe-5.8, linux-kvm,
osv·2021-03-23·CVSS 4.7
[MEDIUM] linux, linux-aws, linux-aws-5.4, linux-azure, linux-azure-5.4, linux-gcp, linux-gcp-5.4, linux-gke-5.3, linux-gke-5.4, linux-gkeop, linux-gkeop-5.4, linux-hwe, linux-hwe-5.4, linux-hwe-5.8, linux-kvm,
linux, linux-aws, linux-aws-5.4, linux-azure, linux-azure-5.4, linux-gcp, linux-gcp-5.4, linux-gke-5.3, linux-gke-5.4, linux-gkeop, linux-gkeop-5.4, linux-hwe, linux-hwe-5.4, linux-hwe-5.8, linux-kvm, linux-oem-5.10, linux-oem-5.6, linux-oracle, linux-oracle-5.4, linux-raspi, linux-raspi-5.4, linux-raspi2-5.3 vulnerabilities
De4dCr0w of 360 Alpha Lab discovered that the BPF verifier in the Linux
kernel did not properly handle mod32 destination register truncation when
the source register was known to be 0. A local attacker could use this to
expose sensitive information (kernel memory) or possibly execute arbitrary
code. (CVE-2021-3444)
Adam Nichols discovered that heap overflows existed in the iSCSI subsystem
in the Linux kernel. A local attacker could use this to cause a denial of
servi
OSV
CVE-2021-3444: The bpf verifier in the Linux kernel did not properly handle mod32 destination register truncation when the source register was known to be 0
osv·2021-03-23·CVSS 7.8
CVE-2021-3444 [HIGH] CVE-2021-3444: The bpf verifier in the Linux kernel did not properly handle mod32 destination register truncation when the source register was known to be 0
The bpf verifier in the Linux kernel did not properly handle mod32 destination register truncation when the source register was known to be 0. A local attacker with the ability to load bpf programs could use this gain out-of-bounds reads in kernel memory leading to information disclosure (kernel memory), and possibly out-of-bounds writes that could potentially lead to code execution. This issue was addressed in the upstream kernel in commit 9b00f1b78809 ("bpf: Fix truncation handling for mod32 dst reg wrt zero") and in Linux stable kernels 5.11.2, 5.10.19, and 5.4.101.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://packetstormsecurity.com/files/162117/Kernel-Live-Patch-Security-Notice-LSN-0075-1.htmlhttp://packetstormsecurity.com/files/164950/Kernel-Live-Patch-Security-Notice-LSN-0082-1.htmlhttp://www.openwall.com/lists/oss-security/2021/03/23/2https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=9b00f1b78809https://lists.debian.org/debian-lts-announce/2021/10/msg00010.htmlhttps://security.netapp.com/advisory/ntap-20210416-0006/https://www.openwall.com/lists/oss-security/2021/03/23/2http://packetstormsecurity.com/files/162117/Kernel-Live-Patch-Security-Notice-LSN-0075-1.htmlhttp://packetstormsecurity.com/files/164950/Kernel-Live-Patch-Security-Notice-LSN-0082-1.htmlhttp://www.openwall.com/lists/oss-security/2021/03/23/2https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=9b00f1b78809https://lists.debian.org/debian-lts-announce/2021/10/msg00010.htmlhttps://security.netapp.com/advisory/ntap-20210416-0006/https://www.openwall.com/lists/oss-security/2021/03/23/2
2021-03-23
Published