CVE-2021-29154 log

Source
Severity Medium
Remote No
Type Privilege escalation
Description
An issue has been discovered in the Linux kernel up to version 5.11.12 that can be abused by unprivileged local users to escalate privileges. The issue is with how BPF JIT compilers for some architectures compute branch displacements when generating machine code. This can be abused to craft anomalous machine code and execute it in the Kernel mode, where the control flow is hijacked to execute unsafe code.
Group Package Affected Fixed Severity Status Ticket
AVG-1799 linux-lts 5.10.28-1 5.10.29-1 Medium Fixed
AVG-1798 linux-zen 5.11.12.zen1-1 5.11.13.zen1-1 Medium Fixed
AVG-1797 linux-hardened 5.11.11.hardened1-1 5.11.13.hardened1-1 Medium Fixed
AVG-1796 linux 5.11.12.arch1-1 5.11.13.arch1-1 Medium Fixed
References
https://www.openwall.com/lists/oss-security/2021/04/08/1
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?h=v5.11.13&id=b85b10dc8af463b59a732f299ade2612a8b950c9
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?h=v5.11.13&id=7f6b5b8e03099559a3c05ce3715c147a1df90bbb
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?h=v5.10.29&id=3edb8967d91ecbc4c5eee34a65d4124267327574
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?h=v5.10.29&id=faa30969f66e74910e9424214a4a426c2dc249d8