CVE-2021-20268: Input Validation
A flaw was found in the Linux kernel. Improper Input Validation in the handling of eBPF programs may lead to privilege escalation.
References:
https://www.zerodayinitiative.com/advisories/ZDI-21-101/
Other sources
An out-of-bounds access flaw was found in the Linux kernel's implementation of the eBPF code verifier in the way a user running the eBPF script calls devmapinitmap or sockmapalloc. This flaw allows a local user to crash the system or possibly escalate their privileges. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
— Launchpad
Affected Software
Remediation
Patch Available
Mitigation
Event History
Frequently Asked Questions
What is the severity of CVE-2021-20268?
CVE-2021-20268 has been classified with a high severity rating due to its potential for privilege escalation.
How do I fix CVE-2021-20268?
To remediate CVE-2021-20268, update the Linux kernel to versions 5.10.10 or newer for Red Hat or the specified patched versions for Debian.
Which Linux distributions are affected by CVE-2021-20268?
CVE-2021-20268 affects multiple Linux distributions including Red Hat and Debian versions prior to the specified patched releases.
What type of vulnerability is CVE-2021-20268?
CVE-2021-20268 is an improper input validation vulnerability in the handling of eBPF programs within the Linux kernel.
Can CVE-2021-20268 be exploited remotely?
Exploitation of CVE-2021-20268 typically requires local access to the system, suggesting it is not directly exploitable remotely.