CVE-2021-38300: High severity Linux Linux kernel vulnerability
arch/mips/net/bpfjit.c in the Linux kernel before 5.4.10 can generate undesirable machine code when transforming unprivileged cBPF programs, allowing execution of arbitrary code within the kernel context. This occurs because conditional branches can exceed the 128 KB limit of the MIPS architecture.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 4.19.249-2Fixed in 4.19.289-2Fixed in 5.10.197-1Fixed in 5.10.191-1Fixed in 6.1.66-1Fixed in 6.1.69-1Fixed in 6.5.13-1Fixed in 6.6.9-1
Event History
Frequently Asked Questions
What is the vulnerability ID of this security issue?
The vulnerability ID is CVE-2021-38300.
What is the severity level of CVE-2021-38300?
The severity level of CVE-2021-38300 is high, with a severity value of 7.8.
Which version of the Linux kernel is affected by CVE-2021-38300?
The Linux kernel versions before 5.4.10 are affected by CVE-2021-38300.
What is the impact of CVE-2021-38300?
CVE-2021-38300 can allow execution of arbitrary code within the kernel context.
Where can I find more information about CVE-2021-38300?
You can find more information about CVE-2021-38300 in the references provided: [Reference 1](https://www.openwall.com/lists/oss-security/2021/09/15/5), [Reference 2](https://lore.kernel.org/bpf/20210915160437.4080-1-piotras@gmail.com/), [Reference 3](https://security-tracker.debian.org/tracker/CVE-2021-38300).