summaryrefslogtreecommitdiffstats
path: root/active/CVE-2021-4001
diff options
context:
space:
mode:
authorSalvatore Bonaccorso <carnil@debian.org>2021-11-24 07:35:42 +0100
committerSalvatore Bonaccorso <carnil@debian.org>2021-11-24 07:35:42 +0100
commite8a532300c04430f851bc06e7f06fb27ed4670c6 (patch)
tree08b55747870cbe2b1a049ce43fe5726c3e53e8cb /active/CVE-2021-4001
parent995d86354de98d66ad34647f9de41f8cd18ea505 (diff)
Add CVE-2021-4001
Diffstat (limited to 'active/CVE-2021-4001')
-rw-r--r--active/CVE-2021-400116
1 files changed, 16 insertions, 0 deletions
diff --git a/active/CVE-2021-4001 b/active/CVE-2021-4001
new file mode 100644
index 00000000..010962e1
--- /dev/null
+++ b/active/CVE-2021-4001
@@ -0,0 +1,16 @@
+Description: bpf: Fix toctou on read-only map's constant scalar tracking
+References:
+ https://bugzilla.redhat.com/show_bug.cgi?id=2025645
+ https://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf.git/commit/?id=353050be4c19e102178ccc05988101887c25ae53
+Notes:
+ carnil> Commit fixes a23740ec43ba ("bpf: Track contents of read-only
+ carnil> maps as scalars") introduced in 5.5-rc1.
+Bugs:
+upstream: released (5.16-rc2) [353050be4c19e102178ccc05988101887c25ae53]
+5.10-upstream-stable: needed
+4.19-upstream-stable: N/A "Vulnerable code introduced later"
+4.9-upstream-stable: N/A "Vulnerable code introduced later"
+sid: needed
+5.10-bullseye-security: needed
+4.19-buster-security: N/A "Vulnerable code introduced later"
+4.9-stretch-security: N/A "Vulnerable code introduced later"

© 2014-2024 Faster IT GmbH | imprint | privacy policy