VDB
BDU%3A2021-04842
BDU%3A2021-04842
PUBLISHED
CVSS 6.800000190734863 MEDIUM
Уязвимость подсистемы eBPF ядра операционной системы Linux , связанная с чтением за границами буфера в памяти, позволяющая нарушителю выполнить произвольный код в контексте ядра
Risk Scores
CVSS 2.0
6.800000190734863
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Сообщество свободного программного обеспечения, Red Hat Inc., Canonical Ltd., Fedora Project, Novell Inc., ООО «Ред Софт», АО "НППКТ" | Debian GNU/Linux, Red Hat Enterprise Linux, Ubuntu, Fedora, OpenSUSE Leap, РЕД ОС (запись в едином реестре российских программ №3751), ОСОН ОСнова Оnyx (запись в едином реестре российских программ №5913), Linux |
Timeline
- Oct 5, 2021 CVE Published
- Mar 1, 2024 PoC Published
- Mar 1, 2024 PoC Published
- Apr 23, 2024 PoC Published
- May 19, 2024 PoC Published
- Jul 17, 2024 PoC Published
- Sep 6, 2024 PoC Published
- Sep 13, 2024 CVE Updated
- Sep 19, 2025 PoC Published
- Nov 17, 2025 PoC Published
- Mar 19, 2026 Distribution Patch
- Mar 19, 2026 Distribution Patch
References
- http://packetstormsecurity.com/files/164015/Linux-eBPF-ALU32-32-bit-Invalid-Bounds-Tracking-Local-Privilege-Escalation.html url
- http://repo.red-soft.ru/redos/7.3c/x86_64/updates/ url
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3490 url
- https://kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.12.4 url
- https://security.netapp.com/advisory/ntap-20210716-0004/ url
- https://ubuntu.com/security/notices/USN-4948-1 url
- https://ubuntu.com/security/notices/USN-4949-1 url
- https://ubuntu.com/security/notices/USN-4950-1 url
- https://usn.ubuntu.com/usn/usn-4948-1 url
- https://usn.ubuntu.com/usn/usn-4949-1 url
- https://usn.ubuntu.com/usn/usn-4950-1 url
- https://www.cve.org/CVERecord?id=CVE-2021-3490 url
- https://www.openwall.com/lists/oss-security/2021/05/11/11 url
- https://www.zerodayinitiative.com/advisories/ZDI-21-606/ url
- https://поддержка.нппкт.рф/bin/view/ОСнова/Обновления/2.4/ url
- https://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf.git/commit/?id=049c4e13714ecbca567b4d5f6d563f05d431c80e advisory
- https://github.com/chompie1337/Linux_LPE_eBPF_CVE-2021-3490 advisory
- https://kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.37 advisory
- https://kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.11.21 advisory
- https://kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.12.4Для advisory
…and 5 more