CVE-2021-31829
Vulnerability Summary
Timeline
Description
kernel/bpf/verifier.c in the Linux kernel through 5.12.1 performs undesirable speculative loads, leading to disclosure of stack content via side-channel attacks, aka CID-801c6058d14a. The specific concern is not protecting the BPF stack area against speculative loads. Also, the BPF stack can contain uninitialized data that might represent sensitive information previously operated on by the kernel.
CVSS Metrics
- v3.1•MEDIUM•Score: 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- v2.0•LOW•Score: 2.1AV:L/AC:L/Au:N/C:P/I:N/A:N
EPSS Trends
Current EPSS score: 0.31%• Percentile: 24%
Techniques & Countermeasures
- CWE-863•Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Affected Systems
- debian•linux
< 5.10.38-1 | < 5.10.38-1 | < 5.10.38-1 | < 5.10.38-1
- ubuntu•linux
all | < 4.15.0-151.157 | < 5.4.0-77.86
- ubuntu•linux-aws
all | < 4.15.0-1109.116 | < 5.4.0-1051.53
- ubuntu•linux-aws-5.0
all
- ubuntu•linux-aws-5.3
all
- ubuntu•linux-aws-5.4
< 5.4.0-1051.53~18.04.1
- ubuntu•linux-aws-5.8
< 5.8.0-1038.40~20.04.1
- ubuntu•linux-aws-fips
< 4.15.0-2051.53 | all | < 5.4.0-1069.73+fips2
- ubuntu•linux-aws-hwe
< 4.15.0-1109.116~16.04.1
- ubuntu•linux-azure
< 4.15.0-1121.134~14.04.1 | < 4.15.0-1121.134~16.04.1 | all | < 5.4.0-1051.53
- ubuntu•linux-azure-4.15
< 4.15.0-1121.134
- ubuntu•linux-azure-5.3
all
- ubuntu•linux-azure-5.4
< 5.4.0-1051.53~18.04.1
- ubuntu•linux-azure-5.8
< 5.8.0-1036.38~20.04.1
- ubuntu•linux-azure-edge
all
- ubuntu•linux-azure-fde-5.15
< 5.15.0-1114.123~20.04.1
- ubuntu•linux-azure-fips
< 4.15.0-2033.37 | all | < 5.4.0-1073.76+fips1
- ubuntu•linux-bluefield
all | < 5.4.0-1013.16
- ubuntu•linux-dell300x
< 4.15.0-1027.32
- ubuntu•linux-fips
all | < 4.15.0-1066.75 | < 5.4.0-1028.32
- ubuntu•linux-gcp
< 4.15.0-1106.120~16.04.1 | all | < 5.4.0-1046.49
- ubuntu•linux-gcp-4.15
< 4.15.0-1106.120
- ubuntu•linux-gcp-5.3
all
- ubuntu•linux-gcp-5.4
< 5.4.0-1046.49~18.04.1
- ubuntu•linux-gcp-5.8
< 5.8.0-1035.37~20.04.1
- ubuntu•linux-gcp-edge
all
- ubuntu•linux-gcp-fips
< 4.15.0-2016.18 | all | < 5.4.0-1067.71~20.04.1
- ubuntu•linux-gke
< 5.4.0-1046.48
- ubuntu•linux-gke-4.15
all
- ubuntu•linux-gke-5.4
< 5.4.0-1046.48~18.04.1
- ubuntu•linux-gkeop
< 5.4.0-1018.19
- ubuntu•linux-gkeop-5.4
< 5.4.0-1018.19~18.04.1
- ubuntu•linux-hwe
< 4.15.0-151.157~16.04.1 | all
- ubuntu•linux-hwe-5.4
< 5.4.0-77.86~18.04.1
- ubuntu•linux-hwe-5.8
< 5.8.0-59.66~20.04.1
- ubuntu•linux-hwe-edge
all | all
- ubuntu•linux-intel-iot-realtime
all
- ubuntu•linux-kvm
all | < 4.15.0-1097.99 | < 5.4.0-1041.42
- ubuntu•linux-lts-xenial
all
- ubuntu•linux-oem
all
- ubuntu•linux-oem-5.10
< 5.10.0-1029.30
- ubuntu•linux-oem-5.6
all
- ubuntu•linux-oracle
< 4.15.0-1078.86~16.04.1 | < 4.15.0-1078.86 | < 5.4.0-1048.52
- ubuntu•linux-oracle-5.0
all
- ubuntu•linux-oracle-5.3
all
- ubuntu•linux-oracle-5.4
< 5.4.0-1048.52~18.04.1
- ubuntu•linux-oracle-5.8
< 5.8.0-1033.34~20.04.1
- ubuntu•linux-raspi
< 5.4.0-1038.41
- ubuntu•linux-raspi-5.4
< 5.4.0-1038.41~18.04.1
- ubuntu•linux-raspi-realtime
all
Showing first 50 affected entries in server-rendered view.
References (17)
- http://www.openwall.com/lists/oss-security/2021/05/04/4
- https://github.com/torvalds/linux/commit/801c6058d14a82179a7ee17a4b532cac6fad067f
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y4X2G5YAPYJGI3PFEZZNOTRYI33GOCCZ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VWCZ6LJLENL2C3URW5ICARTACXPFCFN2/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZI7OBCJQDNWMKLBP6MZ5NV4EUTDAMX6Q/
- https://lists.debian.org/debian-lts-announce/2021/06/msg00019.html
- https://ubuntu.com/security/CVE-2021-31829
- https://www.openwall.com/lists/oss-security/2021/05/04/4
- https://ubuntu.com/security/notices/USN-4983-1
- https://ubuntu.com/security/notices/USN-4997-1
- https://ubuntu.com/security/notices/USN-4999-1
- https://ubuntu.com/security/notices/USN-5000-1
- https://ubuntu.com/security/notices/USN-5018-1
- https://ubuntu.com/security/notices/USN-5000-2
- https://ubuntu.com/security/notices/USN-4997-2
- https://www.cve.org/CVERecord?id=CVE-2021-31829
- https://security-tracker.debian.org/tracker/CVE-2021-31829