CVE-2021-20239
Linux Kernel vulnerability analysis and mitigation

Overview

A flaw was discovered in the Linux kernel versions before 5.4.92 in the BPF (Berkeley Packet Filter) protocol. The vulnerability, identified as CVE-2021-20239, was discovered by Ryota Shiga and allows an attacker with a local account to leak information about kernel internal addresses (CVE Mitre, Ubuntu Security).

Technical details

The vulnerability exists in the sockopt BPF hooks implementation where a user space program can probe for valid kernel addresses. The issue specifically relates to the BPF protocol's handling of setsockopt system calls, where an untrusted pointer dereference can lead to information disclosure. The vulnerability has been assigned a CVSS 3 Severity Score of 3.3 (Low) (Ubuntu Security, Red Hat Bugzilla).

Impact

The highest threat from this vulnerability is to confidentiality. The flaw could allow an attacker to determine the layout of information in kernel memory, which could potentially be used to facilitate future attacks. This information leak may aid an attacker in privilege escalation attempts, although it does not directly enable privilege escalation (Red Hat Bugzilla).

Exploitability

Loading a filter is a privileged operation requiring CAP_SYS_ADMIN or root privileges. However, once any filter is used, the attack can be executed by an unprivileged user. The vulnerability has been documented as ZDI-21-100, and proof-of-concept code has been publicly shared (Red Hat Bugzilla).

Mitigation and workarounds

The vulnerability has been fixed in Linux kernel version 5.4.92 and later. Various Linux distributions have released patches, including Ubuntu 20.04 LTS (fixed in 5.4.0-67.75) and Ubuntu 18.04 LTS (fixed in 5.4.0-67.75~18.04.1). No suitable mitigation was identified for systems that cannot be immediately patched (Ubuntu Security, Red Hat Bugzilla).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-93189HIGH8.8
  • Linux Kernel logoLinux Kernel
  • linux-azure-fips
NoYesSep 17, 2026
CVE-2026-93188MEDIUM6.5
  • Linux Kernel logoLinux Kernel
  • linux-nvidia-tegra-5.15
NoYesSep 17, 2026
CVE-2026-93182NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-fips
NoYesSep 17, 2026
CVE-2026-93181NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-4.15
NoNoSep 17, 2026
CVE-2026-93174NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-fde-6.14
NoYesSep 17, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management