| Severity |
|
| Remote |
|
| Type |
|
| Description |
| + |
It has been discovered that kernel/bpf/verifier.c in the Linux kernel before 4.14.9 allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging mishandling of 32-bit ALU ops. |
|
| References |
| + |
https://bugs.chromium.org/p/project-zero/issues/detail?id=1454 |
| + |
http://www.openwall.com/lists/oss-security/2017/12/21/2 |
| + |
https://git.kernel.org/linus/468f6eafa6c44cb2c5d8aad35e12f06c240a812a |
|
| Notes |
| + |
Workaround by disabling unprivileged bpf: |
| + |
sysctl -w kernel.unprivileged_bpf_disabled=1 |
|