cbcvebase.
CVE-2021-3600
published 2024-01-08

CVE-2021-3600: It was discovered that the eBPF implementation in the Linux kernel did not properly track bounds information for 32 bit registers when performing div and mod…

PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.28%
20.4th percentile
It was discovered that the eBPF implementation in the Linux kernel did not properly track bounds information for 32 bit registers when performing div and mod operations. A local attacker could use this to possibly execute arbitrary code.

Affected

20 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debianlinux< linux 5.10.19-1 (bookworm)linux 5.10.19-1 (bookworm)
fedoraprojectfedora
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.19-15.10.19-1
linuxlinux_kernel>= 0 < 5.10.19-15.10.19-1
linuxlinux_kernel>= 0 < 5.10.19-15.10.19-1
linuxlinux_kernel>= 0 < 5.10.19-15.10.19-1
linuxlinux_kernel>= 0 < 4.15.0-147.1514.15.0-147.151
linuxlinux_kernel>= 0 < 4.4.0-212.2444.4.0-212.244
linuxlinux_kernel>= 0 < 4.15.0-151.1574.15.0-151.157
linuxlinux_kernel>= 0 < 5.4.0-80.905.4.0-80.90
linuxlinux_kernel>= 4.14.115 < 4.14.3084.14.308
linuxlinux_kernel>= 4.15 < 4.19.2064.19.206
linuxlinux_kernel>= 4.20 < 5.4.985.4.98
linuxlinux_kernel>= 5.5 < 5.10.165.10.16
redhatenterprise_linux
the_linux_kernel_organizationlinux< 5.115.11

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.