Vulnerabilities > CVE-2021-3600 - Out-of-bounds Write vulnerability in multiple products

047910
CVSS 7.8 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH

Summary

It was discovered that the eBPF implementation in the Linux kernel did not properly track bounds information for 32 bit registers when performing div and mod operations. A local attacker could use this to possibly execute arbitrary code.

Vulnerable Configurations

Part Description Count
OS
Linux
939
OS
Canonical
3
OS
Fedoraproject
1
OS
Redhat
1

Common Weakness Enumeration (CWE)