CVE-2021-29648 - log back

CVE-2021-29648 edited at 31 Mar 2021 07:42:51
Severity
- Unknown
+ Low
Remote
- Unknown
+ Local
Type
- Unknown
+ Denial of service
Description
+ An issue was discovered in the Linux kernel before 5.11.11. The BPF subsystem does not properly consider that resolved_ids and resolved_sizes are intentionally uninitialized in the vmlinux BPF Type Format (BTF), which can cause a system crash upon an unexpected access attempt (in map_create in kernel/bpf/syscall.c or check_btf_info in kernel/bpf/verifier.c), aka CID-350a5c4dd245.
References
+ https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?h=v5.11.11&id=a9b2ab5db842da37e0f8d830d2a57688d77e3556
CVE-2021-29648 created at 31 Mar 2021 07:37:52
Severity
+ Unknown
Remote
+ Unknown
Type
+ Unknown
Description
References
Notes