CVE-2021-3600: Divide by Zero

Published Jun 23, 2021
·
Updated

A flaw was found in the Linux kernel’s eBPF verification code, where the eBPF 32-bit div/mod source register truncation could lead to out-of-bounds reads and writes. By default, accessing the eBPF verifier is only possible to privileged users with CAPSYSADMIN. This flaw allows a local user who can run eBPF instructions to crash the system or possibly escalate their privileges on the system. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

Other sources

It was discovered that eBPF 32-bit div/mod source register truncation could lead to out-of-bounds reads and writes in the kernel. It was introduced by commit 68fda450a7df ("bpf: fix 32-bit divide by zero"). It was first introduced in 4.15-rc9, but backported and applied to v4.14.y, v4.9.y and v4.4.y. However, this specific attack will not work on v4.4.y and v4.9.y kernels as pointer arithmetic is prohibited on those kernels. This was introduced by commit f1174f77b50c ("bpf/verifier: rework value tracking"), in v4.14-rc1. The fix is commit e88b2c6e5a4d ("bpf: Fix 32 bit src register truncation on div/mod"), introduced in v5.11. It was backported and applied on v5.10.y and v5.4.y, but not v4.19.y and v4.14.y.

Reference: https://www.openwall.com/lists/oss-security/2021/06/23/1

Red Hat

It was discovered that the eBPF implementation in the Linux kernel did not properly track bounds information for 32 bit registers when performing div and mod operations. A local attacker could use this to possibly execute arbitrary code.

Launchpad

Affected Software

20 affected componentsFixes available
redhat/kernel-rt<0:4.18.0-348.rt7.130.el8
0:4.18.0-348.rt7.130.el8
redhat/kernel<0:4.18.0-348.el8
0:4.18.0-348.el8
redhat/Kernel<5.11
5.11
Linux Linux kernel>=4.14.115<4.14.308
Linux Linux kernel>=4.15<4.19.206
Linux Linux kernel>=4.20<5.4.98
Linux Linux kernel>=5.5<5.10.16
Linux Linux kernel=5.11-rc1
Linux Linux kernel=5.11-rc2
Linux Linux kernel=5.11-rc3
Linux Linux kernel=5.11-rc4
Linux Linux kernel=5.11-rc5
Linux Linux kernel=5.11-rc6
Linux Linux kernel=5.11-rc7
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Fedoraproject Fedora=34
redhat Enterprise Linux=8.0
debian/linux
5.10.223-15.10.234-16.1.129-16.1.133-16.12.21-16.12.22-1

Remediation

Information

The default Red Hat Enterprise Linux kernel prevents unprivileged users from being able to use eBPF by the kernel.unprivileged_bpf_disabled sysctl. This would require a privileged user with CAP_SYS_ADMIN or root to be able to abuse this flaw reducing its attack space. For the Red Hat Enterprise Linux 7 the eBPF for unprivileged users is always disabled. For the Red Hat Enterprise Linux 8 to confirm the current state, inspect the sysctl with the command: # cat /proc/sys/kernel/unprivileged_bpf_disabled The setting of 1 would mean that unprivileged users can not use eBPF, mitigating the flaw. A kernel update will be required to mitigate the flaw for the root or users with CAP_SYS_ADMIN capabilities.

Event History

Jun 23, 2021
CVE Published
12:00 AM
Jan 8, 2024
CVE Published
via MITRE·06:16 PM
Data Sourced
via MITRE·06:16 PM
DescriptionSeverity
Jan 11, 2024
Data Sourced
via Launchpad·11:57 PM
Description
Apr 16, 2025
Data Sourced
via Ubuntu·03:44 AM
RemedyDescriptionSeverityAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Frequently Asked Questions

1

What is the severity of CVE-2021-3600?

CVE-2021-3600 has a medium severity rating due to its potential for local privilege escalation.

2

How do I fix CVE-2021-3600?

To fix CVE-2021-3600, upgrade to the kernel versions specified in the remediation details or install the provided patches.

3

What software is affected by CVE-2021-3600?

CVE-2021-3600 affects various versions of the Linux kernel, specifically those prior to the fixed versions stated in the remediation.

4

Is CVE-2021-3600 exploitable remotely?

No, CVE-2021-3600 is only exploitable locally by users with specific privileges.

5

What types of vulnerabilities are related to CVE-2021-3600?

CVE-2021-3600 is related to local privilege escalation through out-of-bounds read and write vulnerabilities.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203