CVE-2021-31829: Infoleak

Published Apr 30, 2021
·
Updated

A flaw was found in the Linux kernel's eBPF verification code. By default, accessing the eBPF verifier is only accessible to privileged users with CAPSYSADMIN. This flaw allows a local user who can insert eBPF instructions, to use the eBPF verifier to abuse a spectre-like flaw and infer all system memory. The highest threat from this vulnerability is to confidentiality.

Other sources

kernel/bpf/verifier.c in the Linux kernel through 5.12.1 performs undesirable speculative loads, leading to disclosure of stack content via side-channel attacks, aka CID-801c6058d14a. The specific concern is not protecting the BPF stack area against speculative loads. Also, the BPF stack can contain uninitialized data that might represent sensitive information previously operated on by the kernel.

Programs inserted by privileged users can run Privileged BPF programs running on affected systems can bypass the protection and execute speculative loads from the kernel stack. This can be abused to extract contents of the stack via side-channel. The extracted contents may include addresses of kernel structures that could be used to defeat Kernel Address Space Layout Randomization (KASLR) to facilitate the exploitation of other vulnerabilities.

Reference: https://www.openwall.com/lists/oss-security/2021/05/04/4

Upstream patches: https://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf.git/patch/?id=b9b34ddbe2076ade359cd5ce7537d5ed019e9807 https://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf.git/patch/?id=801c6058d14a82179a7ee17a4b532cac6fad067f

Red Hat

Affected Software

8 affected componentsFixes available
redhat/kernel-rt<0:4.18.0-348.rt7.130.el8
0:4.18.0-348.rt7.130.el8
redhat/kernel<0:4.18.0-348.el8
0:4.18.0-348.el8
Linux Linux kernel<=5.12.1
Fedoraproject Fedora=32
Fedoraproject Fedora=33
Fedoraproject Fedora=34
Debian Debian Linux=9.0
debian/linux
5.10.223-15.10.234-16.1.129-16.1.135-16.12.25-16.12.27-1

Remediation

Information

The default Red Hat Enterprise Linux kernel prevents unprivileged users from being able to use eBPF by the kernel.unprivileged_bpf_disabled sysctl. This would require a privileged user with CAP_SYS_ADMIN or root to be able to abuse this flaw reducing its attack space. For the Red Hat Enterprise Linux 7 and 8 kernel to confirm the current state, inspect the sysctl with the command: # cat /proc/sys/kernel/unprivileged_bpf_disabled The setting of 1 would mean that unprivileged users can not use eBPF, mitigating the flaw. A kernel update will be required to mitigate the flaw for the root or users with CAP_SYS_ADMIN capabilities.

Event History

Apr 30, 2021
CVE Published
12:00 AM
May 6, 2021
Data Sourced
via Red Hat·01:37 PM
DescriptionSeverityAffected Software
CVE Published
via MITRE·03:43 PM
Data Sourced
via MITRE·03:43 PM
Description
Jan 11, 2024
Data Sourced
via Launchpad·11:56 PM
Description
Apr 28, 2025
Data Sourced
via Ubuntu·04:26 AM
RemedyDescriptionSeverityAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Frequently Asked Questions

1

What is the severity of CVE-2021-31829?

CVE-2021-31829 is considered to have a high severity due to its potential impact on system security.

2

How do I fix CVE-2021-31829?

To fix CVE-2021-31829, update your kernel to versions 0:4.18.0-348.rt7.130.el8, 0:4.18.0-348.el8 for Red Hat, or apply the corresponding updates for your Linux distribution.

3

Which Linux distributions are affected by CVE-2021-31829?

CVE-2021-31829 affects various Linux distributions including Red Hat, Fedora versions 32, 33, 34, and Debian 9.0.

4

What kind of vulnerability is CVE-2021-31829?

CVE-2021-31829 is a local privilege escalation vulnerability related to eBPF verification in the Linux kernel.

5

Who can exploit CVE-2021-31829?

CVE-2021-31829 can be exploited by a local user with the ability to insert eBPF instructions to infer sensitive system information.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203