Unrated severityNVD Advisory· Published May 6, 2021· Updated Aug 3, 2024
CVE-2021-31829
CVE-2021-31829
Description
kernel/bpf/verifier.c in the Linux kernel through 5.12.1 performs undesirable speculative loads, leading to disclosure of stack content via side-channel attacks, aka CID-801c6058d14a. The specific concern is not protecting the BPF stack area against speculative loads. Also, the BPF stack can contain uninitialized data that might represent sensitive information previously operated on by the kernel.
Affected products
2- Linux/Linux kerneldescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VWCZ6LJLENL2C3URW5ICARTACXPFCFN2/mitrevendor-advisoryx_refsource_FEDORA
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y4X2G5YAPYJGI3PFEZZNOTRYI33GOCCZ/mitrevendor-advisoryx_refsource_FEDORA
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZI7OBCJQDNWMKLBP6MZ5NV4EUTDAMX6Q/mitrevendor-advisoryx_refsource_FEDORA
- www.openwall.com/lists/oss-security/2021/05/04/4mitremailing-listx_refsource_MLISTx_refsource_MISC
- github.com/torvalds/linux/commit/801c6058d14a82179a7ee17a4b532cac6fad067fmitrex_refsource_MISC
- lists.debian.org/debian-lts-announce/2021/06/msg00019.htmlmitremailing-listx_refsource_MLIST
News mentions
0No linked articles in our index yet.