CVE-2021-46908

Advisory lineage Upstream: 0 Downstream: 4
Modified
Published: 27 Feb 2024, 06:53
Last modified:11 May 2026, 13:44

Vulnerability Summary

Overall Risk (default)
low
22/100
CVSS Score
5.5 MEDIUM
v3.1 (nvd)
EPSS Score
<0.01% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

27 Feb 2024, 06:53
Published
Vulnerability first disclosed
11 May 2026, 13:44
Last Modified
Vulnerability information updated

Description

In the Linux kernel, the following vulnerability has been resolved: bpf: Use correct permission flag for mixed signed bounds arithmetic We forbid adding unknown scalars with mixed signed bounds due to the spectre v1 masking mitigation. Hence this also needs bypass_spec_v1 flag instead of allow_ptr_leaks.

CVSS Metrics

  • v3.1MEDIUMScore: 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 0.00% Percentile: 0%

Affected Systems

  • linuxlinux

    ≥ 2c78ee898d8f10ae6fb2fa23a3fbaec96b1b7366, < 4f3ff11204eac0ee23acf64deecb3bad7b0db0c6 | ≥ 2c78ee898d8f10ae6fb2fa23a3fbaec96b1b7366, < 4ccdc6c6cae38b91c871293fb0ed8c6845a61b51 | ≥ 2c78ee898d8f10ae6fb2fa23a3fbaec96b1b7366, < 9601148392520e2e134936e76788fc2a6371e7be | 5.8

  • linuxlinux_kernel

    ≥ 5.8.0, < 5.10.32 | ≥ 5.11.0, < 5.11.16

References (3)