CVE-2021-34866
published 2022-01-25CVE-2021-34866: This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel 5.14-rc3. An attacker must first obtain the ability…
PriorityP345high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.97%
58.0th percentile
This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel 5.14-rc3. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of eBPF programs. The issue results from the lack of proper validation of user-supplied eBPF programs, which can result in a type confusion condition. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the kernel. Was ZDI-CAN-14689.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.14.6-1 (bookworm) | linux 5.14.6-1 (bookworm) |
| linux | kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.70-1 | 5.10.70-1 |
| linux | linux_kernel | >= 0 < 5.14.6-1 | 5.14.6-1 |
| linux | linux_kernel | >= 0 < 5.14.6-1 | 5.14.6-1 |
| linux | linux_kernel | >= 0 < 5.14.6-1 | 5.14.6-1 |
| linux | linux_kernel | >= 5.11 < 5.13.14 | 5.13.14 |
| linux | linux_kernel | >= 5.8 < 5.10.62 | 5.10.62 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv3.08.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: eBPF verification flaw
vendor_redhat·2021-10-13·CVSS 7.8
CVE-2021-34866 [HIGH] CWE-697 kernel: eBPF verification flaw
kernel: eBPF verification flaw
This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel 5.14-rc3. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of eBPF programs. The issue results from the lack of proper validation of user-supplied eBPF programs, which can result in a type confusion condition. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the kernel. Was ZDI-CAN-14689.
A vulnerability was found in Linux Kernel, where a type confusion problem in check_map_func_compatibility() may lead to free arbitrary kernel memory.
Mitigation: The default Re
Debian
CVE-2021-34866: linux - This vulnerability allows local attackers to escalate privileges on affected ins...
vendor_debian·2021·CVSS 7.8
CVE-2021-34866 [HIGH] CVE-2021-34866: linux - This vulnerability allows local attackers to escalate privileges on affected ins...
This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel 5.14-rc3. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of eBPF programs. The issue results from the lack of proper validation of user-supplied eBPF programs, which can result in a type confusion condition. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the kernel. Was ZDI-CAN-14689.
Scope: local
bookworm: resolved (fixed in 5.14.6-1)
bullseye: resolved (fixed in 5.10.70-1)
forky: resolved (fixed in 5.14.6-1)
sid: resolved (fixed in 5.14.6-1)
trixie: resolved (fixed in 5.14.6-1)
OSV
CVE-2021-34866: In check_map_func_compatibility of verifier
osv·2022-04-01
CVE-2021-34866 CVE-2021-34866: In check_map_func_compatibility of verifier
In check_map_func_compatibility of verifier.c, there is a possible way to escalate privileges due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
GHSA
GHSA-mrjq-f7fw-fmg2: This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel 5
ghsa_unreviewed·2022-01-26
CVE-2021-34866 [HIGH] CWE-843 GHSA-mrjq-f7fw-fmg2: This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel 5
This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel 5.14-rc3. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of eBPF programs. The issue results from the lack of proper validation of user-supplied eBPF programs, which can result in a type confusion condition. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the kernel. Was ZDI-CAN-14689.
OSV
CVE-2021-34866: This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel 5
osv·2022-01-25·CVSS 7.8
CVE-2021-34866 [HIGH] CVE-2021-34866: This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel 5
This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel 5.14-rc3. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of eBPF programs. The issue results from the lack of proper validation of user-supplied eBPF programs, which can result in a type confusion condition. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the kernel. Was ZDI-CAN-14689.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2021-34866 kernel: eBPF verification flaw
bugzilla·2021-09-02·CVSS 7.8
CVE-2021-34866 [HIGH] CVE-2021-34866 kernel: eBPF verification flaw
CVE-2021-34866 kernel: eBPF verification flaw
A vulnerability was found in Linux Kernel, where a type confusion problem in check_map_func_compatibility() may lead to free arbitrary kernel memory.
Reference:
https://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf.git/commit/?id=5b029a32cfe4600f5e10e36b41778506b90fd4de
https://www.zerodayinitiative.com/advisories/ZDI-21-1148/
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8.6 Extended Update Support
Via RHSA-2024:0724 https://access.redhat.com/errata/RHSA-2024:0724
arXiv
KernJC: Automated Vulnerable Environment Generation for Linux Kernel Vulnerabilities
arxiv_fulltext·2024-09-24
KernJC: Automated Vulnerable Environment Generation for Linux Kernel Vulnerabilities
: Automated Vulnerable Environment Generation for Linux Kernel Vulnerabilities
Bonan Ruan
National University of Singapore
Jiahao Liu
National University of Singapore
Chuqi Zhang
National University of Singapore
Zhenkai Liang
National University of Singapore
## Abstract
Linux kernel vulnerability reproduction is a critical task in system security.
To reproduce a kernel vulnerability, the vulnerable environment and the Proof of Concept (PoC) program are needed.
Most existing research focuses on the generation of PoC, while the construction of environment is overlooked.
However, establishing an effective vulnerable environment to trigger a vulnerability is challenging.
Firstly, it is hard to guarantee that the selected kernel version for reproduction is vulnerable, as the vulner
arXiv
SafeBPF: Hardware-assisted Defense-in-depth for eBPF Kernel Extensions
arxiv_fulltext·2024-09-11
SafeBPF: Hardware-assisted Defense-in-depth for eBPF Kernel Extensions
: Hardware-assisted Defense-in-depth for Kernel Extensions
Soo Yee Lim
[email protected]
0000-0002-3418-4982
University of British Columbia
Vancouver
British Columbia
Canada
Tanya Prasad
[email protected]
0009-0000-5378-1857
University of British Columbia
Vancouver
British Columbia
Canada
Xueyuan Han
[email protected]
0000-0003-1374-153X
Wake Forest University
Winston-Salem
North Carolina
USA
Thomas Pasquier
[email protected]
0000-0001-6876-1306
University of British Columbia
Vancouver
British Columbia
Canada
## Abstract
The framework enables
execution
of user-provided code
in the Linux kernel.
In the last few years,
a large ecosystem of cloud services has leveraged to enhance container security, system observability, and network management.
Meanwhile,
incessant discoveries
of memory
2022-01-25
Published