CVE-2021-33624: Medium severity linux kernel vulnerability
In kernel/bpf/verifier.c in the Linux kernel before 5.12.13, a branch can be mispredicted (e.g., because of type confusion) and consequently an unprivileged BPF program can read arbitrary memory locations via a side-channel attack, aka CID-9183671af6db.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2021-33624?
CVE-2021-33624 is classified as a medium severity vulnerability due to its potential to allow unprivileged BPF programs to read arbitrary memory locations.
How do I fix CVE-2021-33624?
To resolve CVE-2021-33624, update your Linux kernel to version 5.12.13 or later.
What type of attack does CVE-2021-33624 involve?
CVE-2021-33624 involves a side-channel attack enabled by branch misprediction due to type confusion in the BPF verifier.
Which versions of the Linux kernel are affected by CVE-2021-33624?
CVE-2021-33624 affects Linux kernel versions prior to 5.12.13.
Are there specific distributions impacted by CVE-2021-33624?
Yes, Debian and its variants are among the affected distributions for CVE-2021-33624.