CVE-2021-39711
published 2022-03-16CVE-2021-39711: In bpf_prog_test_run_skb of test_run.c, there is a possible out of bounds read due to Incorrect Size Value. This could lead to local information disclosure…
PriorityP416medium4.4CVSS 3.1
AVLACLPRHUINSUCHINAN
EPSS
0.15%
5.0th percentile
In bpf_prog_test_run_skb of test_run.c, there is a possible out of bounds read due to Incorrect Size Value. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-154175781References: Upstream kernel
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.18.6-1 (bookworm) | linux 4.18.6-1 (bookworm) |
| linux | linux_kernel | >= 0 < 4.18.6-1 | 4.18.6-1 |
| linux | linux_kernel | >= 0 < 4.18.6-1 | 4.18.6-1 |
| linux | linux_kernel | >= 0 < 4.18.6-1 | 4.18.6-1 |
| linux | linux_kernel | >= 0 < 4.18.6-1 | 4.18.6-1 |
CVSS provenance
nvdv3.14.4MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv4.4MEDIUM
vendor_debian4.4MEDIUM
vendor_redhat4.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8g4m-8c8j-3c2f: In bpf_prog_test_run_skb of test_run
ghsa_unreviewed·2022-03-17
CVE-2021-39711 [MEDIUM] CWE-125 GHSA-8g4m-8c8j-3c2f: In bpf_prog_test_run_skb of test_run
In bpf_prog_test_run_skb of test_run.c, there is a possible out of bounds read due to Incorrect Size Value. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-154175781References: Upstream kernel
OSV
CVE-2021-39711: In bpf_prog_test_run_skb of test_run
osv·2022-03-16·CVSS 4.4
CVE-2021-39711 [MEDIUM] CVE-2021-39711: In bpf_prog_test_run_skb of test_run
In bpf_prog_test_run_skb of test_run.c, there is a possible out of bounds read due to Incorrect Size Value. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-154175781References: Upstream kernel
OSV
CVE-2021-39711: In bpf_prog_test_run_skb of test_run
osv·2022-03-01
CVE-2021-39711 CVE-2021-39711: In bpf_prog_test_run_skb of test_run
In bpf_prog_test_run_skb of test_run.c, there is a possible out of bounds read due to Incorrect Size Value. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
Red Hat
kernel: out-of-bounds read due to Incorrect size value in bpf_prog_test_run_skb() of test_run.c
vendor_redhat·2022-03-07·CVSS 4.4
CVE-2021-39711 [MEDIUM] CWE-125 kernel: out-of-bounds read due to Incorrect size value in bpf_prog_test_run_skb() of test_run.c
kernel: out-of-bounds read due to Incorrect size value in bpf_prog_test_run_skb() of test_run.c
In bpf_prog_test_run_skb of test_run.c, there is a possible out of bounds read due to Incorrect Size Value. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-154175781References: Upstream kernel
An out-of-bounds (OOB) read flaw was found in bpf_prog_test_run_skb in the net/bpf/test_run.c function due to an incorrect Size Value in the Linux kernel.
Statement: There was no shipped kernel version that was seen affected by this problem.
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2021-39711: linux - In bpf_prog_test_run_skb of test_run.c, there is a possible out of bounds read d...
vendor_debian·2021·CVSS 4.4
CVE-2021-39711 [MEDIUM] CVE-2021-39711: linux - In bpf_prog_test_run_skb of test_run.c, there is a possible out of bounds read d...
In bpf_prog_test_run_skb of test_run.c, there is a possible out of bounds read due to Incorrect Size Value. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-154175781References: Upstream kernel
Scope: local
bookworm: resolved (fixed in 4.18.6-1)
bullseye: resolved (fixed in 4.18.6-1)
forky: resolved (fixed in 4.18.6-1)
sid: resolved (fixed in 4.18.6-1)
trixie: resolved (fixed in 4.18.6-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-03-16
Published