CVE-2021-35477
⚪ Do wiadomości
Atak Speculative Store Bypass w jądrze Linux pozwala nieuprzywilejowanym programom BPF na wyciek wrażliwych danych z pamięci jądra.
CVSS
5.5
EPSS
0.5%
Exploit
none
Vendor
fedoraproject
Opis źródłowy (NVD)
In the Linux kernel through 5.13.7, an unprivileged BPF program can obtain sensitive information from kernel memory via a Speculative Store Bypass side-channel attack because a certain preempting store operation does not necessarily occur before a store operation that has an attacker-controlled value.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 5.5 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.5% |
| Opublikowano (NVD) | 2021-08-02 04:15:07 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-08 21:17:36 UTC |
Referencje
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=2039f26f3aca5b0e419b98f65dd36481337b86ee ([email protected]) [Patch, Vendor Advisory]
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=f5e81d1117501546b7be050c5fbafa6efd2c722c ([email protected]) [Patch, Vendor Advisory]
- https://lists.debian.org/debian-lts-announce/2021/10/msg00010.html ([email protected]) [Mailing List, Third Party Advisory]
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/565ZS55ZFEN62WVRRORT7R63RXW5F4T4/ ([email protected])
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6JKK6XNRZX5BT5QVYOKGVJ2BHFZAP5EX/ ([email protected])
- https://www.openwall.com/lists/oss-security/2021/08/01/3 ([email protected]) [Mailing List, Third Party Advisory]