CVE-2021-3490 - log back

CVE-2021-3490 edited at 14 May 2021 22:10:29
References
https://www.openwall.com/lists/oss-security/2021/05/11/11
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?h=v5.12.4&id=9fdd1d10daac186e21a77290f9d22b41e175e1b9
- https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?h=v5.11.21&id=646f2a9b0ecc57817352830d4efa409d89542e1d
+ https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?h=v5.11.21&id=3a0066086a338f99205b1c38c9fbefaeb5cd6d28
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?h=v5.10.37&id=282bfc8848eaa195d5e994bb700f2c7afb7eb3e6
CVE-2021-3490 edited at 14 May 2021 22:07:41
References
https://www.openwall.com/lists/oss-security/2021/05/11/11
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?h=v5.12.4&id=9fdd1d10daac186e21a77290f9d22b41e175e1b9
+ https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?h=v5.11.21&id=646f2a9b0ecc57817352830d4efa409d89542e1d
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?h=v5.10.37&id=282bfc8848eaa195d5e994bb700f2c7afb7eb3e6
CVE-2021-3490 edited at 14 May 2021 15:47:16
Description
- A security issue was found in the Linux kernel. It was discovered that eBPF ALU32 bounds tracking for bitwise ops (AND, OR and XOR) did not update the 32-bit bounds, leading to out-of-bounds reads and writes in the kernel.
+ A security issue was found in the Linux kernel before version 5.12.4. It was discovered that eBPF ALU32 bounds tracking for bitwise ops (AND, OR and XOR) did not update the 32-bit bounds, leading to out-of-bounds reads and writes in the kernel.
References
https://www.openwall.com/lists/oss-security/2021/05/11/11
- https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/kernel/bpf/verifier.c?h=v5.12.4&id=9fdd1d10daac186e21a77290f9d22b41e175e1b9
+ https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?h=v5.12.4&id=9fdd1d10daac186e21a77290f9d22b41e175e1b9
- https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/kernel/bpf/verifier.c?h=v5.10.37&id=282bfc8848eaa195d5e994bb700f2c7afb7eb3e6
+ https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?h=v5.10.37&id=282bfc8848eaa195d5e994bb700f2c7afb7eb3e6
CVE-2021-3490 edited at 14 May 2021 15:37:32
References
https://www.openwall.com/lists/oss-security/2021/05/11/11
- https://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf.git/commit/?id=049c4e13714ecbca567b4d5f6d563f05d431c80e
+ https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/kernel/bpf/verifier.c?h=v5.12.4&id=9fdd1d10daac186e21a77290f9d22b41e175e1b9
+ https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/kernel/bpf/verifier.c?h=v5.10.37&id=282bfc8848eaa195d5e994bb700f2c7afb7eb3e6
CVE-2021-3490 edited at 11 May 2021 18:08:53
Severity
- Unknown
+ Medium
Remote
- Unknown
+ Local
Type
- Unknown
+ Arbitrary code execution
Description
+ A security issue was found in the Linux kernel. It was discovered that eBPF ALU32 bounds tracking for bitwise ops (AND, OR and XOR) did not update the 32-bit bounds, leading to out-of-bounds reads and writes in the kernel.
References
+ https://www.openwall.com/lists/oss-security/2021/05/11/11
+ https://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf.git/commit/?id=049c4e13714ecbca567b4d5f6d563f05d431c80e
CVE-2021-3490 created at 11 May 2021 18:04:24
Severity
+ Unknown
Remote
+ Unknown
Type
+ Unknown
Description
References
Notes