CVE-2021-3600
published 2024-01-08CVE-2021-3600: It was discovered that the eBPF implementation in the Linux kernel did not properly track bounds information for 32 bit registers when performing div and mod…
PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.28%
20.4th percentile
It was discovered that the eBPF implementation in the Linux kernel did not properly track bounds information for 32 bit registers when performing div and mod operations. A local attacker could use this to possibly execute arbitrary code.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | linux | < linux 5.10.19-1 (bookworm) | linux 5.10.19-1 (bookworm) |
| fedoraproject | fedora | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.19-1 | 5.10.19-1 |
| linux | linux_kernel | >= 0 < 5.10.19-1 | 5.10.19-1 |
| linux | linux_kernel | >= 0 < 5.10.19-1 | 5.10.19-1 |
| linux | linux_kernel | >= 0 < 5.10.19-1 | 5.10.19-1 |
| linux | linux_kernel | >= 0 < 4.15.0-147.151 | 4.15.0-147.151 |
| linux | linux_kernel | >= 0 < 4.4.0-212.244 | 4.4.0-212.244 |
| linux | linux_kernel | >= 0 < 4.15.0-151.157 | 4.15.0-151.157 |
| linux | linux_kernel | >= 0 < 5.4.0-80.90 | 5.4.0-80.90 |
| linux | linux_kernel | >= 4.14.115 < 4.14.308 | 4.14.308 |
| linux | linux_kernel | >= 4.15 < 4.19.206 | 4.19.206 |
| linux | linux_kernel | >= 4.20 < 5.4.98 | 5.4.98 |
| linux | linux_kernel | >= 5.5 < 5.10.16 | 5.10.16 |
| redhat | enterprise_linux | — | — |
| the_linux_kernel_organization | linux | < 5.11 | 5.11 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Kernel Live Patch Security Notice
vendor_ubuntu·2021-07-26·CVSS 7.8
CVE-2021-3600 [HIGH] Kernel Live Patch Security Notice
Title: Kernel Live Patch Security Notice
Summary: Several security issues were fixed in the kernel.
It was discovered that the eBPF implementation in the Linux kernel did not
properly track bounds information for 32 bit registers when performing div
and mod operations. A local attacker could use this to possibly execute
arbitrary code.(CVE-2021-3600)
It was discovered that the virtual file system implementation in the Linux
kernel contained an unsigned to signed integer conversion error. A local
attacker could use this to cause a denial of service (system crash) or
execute arbitrary code.(CVE-2021-33909)
Red Hat
kernel: eBPF 32-bit source register truncation on div/mod
vendor_redhat·2021-06-23·CVSS 7.8
CVE-2021-3600 [HIGH] CWE-787 kernel: eBPF 32-bit source register truncation on div/mod
kernel: eBPF 32-bit source register truncation on div/mod
It was discovered that the eBPF implementation in the Linux kernel did not properly track bounds information for 32 bit registers when performing div and mod operations. A local attacker could use this to possibly execute arbitrary code.
A flaw was found in the Linux kernel’s eBPF verification code, where the eBPF 32-bit div/mod source register truncation could lead to out-of-bounds reads and writes. By default, accessing the eBPF verifier is only possible to privileged users with CAP_SYS_ADMIN. This flaw allows a local user who can run eBPF instructions to crash the system or possibly escalate their privileges on the system. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availabilit
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2021-06-23·CVSS 6.7
CVE-2021-23133 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Norbert Slusarek discovered a race condition in the CAN BCM networking
protocol of the Linux kernel leading to multiple use-after-free
vulnerabilities. A local attacker could use this issue to execute arbitrary
code. (CVE-2021-3609)
It was discovered that the eBPF implementation in the Linux kernel did not
properly track bounds information for 32 bit registers when performing div
and mod operations. A local attacker could use this to possibly execute
arbitrary code. (CVE-2021-3600)
Or Cohen discovered that the SCTP implementation in the Linux kernel
contained a race condition in some situations, leading to a use-after-free
condition. A local attacker could use this to cause a denial of
Debian
CVE-2021-3600: linux - It was discovered that the eBPF implementation in the Linux kernel did not prope...
vendor_debian·2021·CVSS 7.8
CVE-2021-3600 [HIGH] CVE-2021-3600: linux - It was discovered that the eBPF implementation in the Linux kernel did not prope...
It was discovered that the eBPF implementation in the Linux kernel did not properly track bounds information for 32 bit registers when performing div and mod operations. A local attacker could use this to possibly execute arbitrary code.
Scope: local
bookworm: resolved (fixed in 5.10.19-1)
bullseye: resolved (fixed in 5.10.19-1)
forky: resolved (fixed in 5.10.19-1)
sid: resolved (fixed in 5.10.19-1)
trixie: resolved (fixed in 5.10.19-1)
GHSA
GHSA-769h-g9v6-cwg7: It was discovered that the eBPF implementation in the Linux kernel did not properly track bounds information for 32 bit registers when performing div
ghsa_unreviewed·2024-01-08
CVE-2021-3600 [HIGH] CWE-125 GHSA-769h-g9v6-cwg7: It was discovered that the eBPF implementation in the Linux kernel did not properly track bounds information for 32 bit registers when performing div
It was discovered that the eBPF implementation in the Linux kernel did not properly track bounds information for 32 bit registers when performing div and mod operations. A local attacker could use this to possibly execute arbitrary code.
OSV
CVE-2021-3600: It was discovered that the eBPF implementation in the Linux kernel did not properly track bounds information for 32 bit registers when performing div
osv·2024-01-08·CVSS 7.8
CVE-2021-3600 [HIGH] CVE-2021-3600: It was discovered that the eBPF implementation in the Linux kernel did not properly track bounds information for 32 bit registers when performing div
It was discovered that the eBPF implementation in the Linux kernel did not properly track bounds information for 32 bit registers when performing div and mod operations. A local attacker could use this to possibly execute arbitrary code.
OSV
Kernel Live Patch Security Notice
osv·2021-07-26·CVSS 7.8
CVE-2021-3600 [HIGH] Kernel Live Patch Security Notice
Kernel Live Patch Security Notice
It was discovered that the eBPF implementation in the Linux kernel did not
properly track bounds information for 32 bit registers when performing div
and mod operations. A local attacker could use this to possibly execute
arbitrary code.(CVE-2021-3600)
It was discovered that the virtual file system implementation in the Linux
kernel contained an unsigned to signed integer conversion error. A local
attacker could use this to cause a denial of service (system crash) or
execute arbitrary code.(CVE-2021-33909)
OSV
linux, linux-aws, linux-aws-hwe, linux-azure, linux-azure-4.15, linux-dell300x, linux-gcp, linux-gcp-4.15, linux-hwe, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities
osv·2021-06-23·CVSS 7.0
CVE-2021-3609 [HIGH] linux, linux-aws, linux-aws-hwe, linux-azure, linux-azure-4.15, linux-dell300x, linux-gcp, linux-gcp-4.15, linux-hwe, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities
linux, linux-aws, linux-aws-hwe, linux-azure, linux-azure-4.15, linux-dell300x, linux-gcp, linux-gcp-4.15, linux-hwe, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities
Norbert Slusarek discovered a race condition in the CAN BCM networking
protocol of the Linux kernel leading to multiple use-after-free
vulnerabilities. A local attacker could use this issue to execute arbitrary
code. (CVE-2021-3609)
It was discovered that the eBPF implementation in the Linux kernel did not
properly track bounds information for 32 bit registers when performing div
and mod operations. A local attacker could use this to possibly execute
arbitrary code. (CVE-2021-3600)
Or Cohen discovered that the SCTP implementation in the Linux kernel
contained a race condition in some situations, leading to a us
Suricata
ET EXPLOIT Realtek SDK - Command Execution/Backdoor Access Inbound (CVE-2021-35394)
suricata·2023-01-27·CVSS 9.8
CVE-2021-35394 [CRITICAL] ET EXPLOIT Realtek SDK - Command Execution/Backdoor Access Inbound (CVE-2021-35394)
ET EXPLOIT Realtek SDK - Command Execution/Backdoor Access Inbound (CVE-2021-35394)
Rule: alert udp any any -> $HOME_NET 9034 (msg:"ET EXPLOIT Realtek SDK - Command Execution/Backdoor Access Inbound (CVE-2021-35394)"; flow:to_server; content:"orf|3b|"; fast_pattern; startswith; threshold:type limit, count 1, seconds 3600, track by_src; reference:cve,2021-35394; reference:url,unit42.paloaltonetworks.com/realtek-sdk-vulnerability/; reference:url,onekey.com/blog/advisory-multiple-issues-realtek-sdk-iot-supply-chain; classtype:attempted-admin; sid:2044008; rev:2; metadata:affected_product IoT, attack_target Networking_Equipment, created_at 2023_01_27, cve CVE_2021_35394, deployment Perimeter, deployment Internal, performance_impact Low, confidence High, signature_severity Major, tag CISA_KEV,
Nuclei
Auerswald COMfortel 1400/2600/3600 IP - Authentication Bypass
nuclei·CVSS 7.5
CVE-2021-40856 [HIGH] Auerswald COMfortel 1400/2600/3600 IP - Authentication Bypass
Auerswald COMfortel 1400/2600/3600 IP - Authentication Bypass
Auerswald COMfortel 1400/2600/3600 IP is susceptible to an authentication bypass vulnerability. Inserting the prefix "/about/../" allows bypassing the authentication check for the web-based configuration management interface. This enables attackers to gain access to the login credentials used for authentication at the PBX, among other data.
Template:
id: CVE-2021-40856
info:
name: Auerswald COMfortel 1400/2600/3600 IP - Authentication Bypass
author: gy741
severity: high
description: Auerswald COMfortel 1400/2600/3600 IP is susceptible to an authentication bypass vulnerability. Inserting the prefix "/about/../" allows bypassing the authentication check for the web-based configuration management interface. This enables attacke
No writeups or analysis indexed.
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3600https://git.kernel.org/linus/e88b2c6e5a4d9ce30d75391e4d950da74bb2bd90https://ubuntu.com/security/notices/USN-5003-1https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3600https://git.kernel.org/linus/e88b2c6e5a4d9ce30d75391e4d950da74bb2bd90https://ubuntu.com/security/notices/USN-5003-1
2024-01-08
Published