
Cloud Vulnerability DB
A community-led vulnerabilities database
An out-of-bounds access vulnerability (CVE-2021-20268) was discovered in the Linux kernel's implementation of the eBPF code verifier, specifically in how a user running the eBPF script calls dev_map_init_map or sock_map_alloc. The vulnerability was disclosed on March 9, 2021, affecting Linux kernel versions prior to 5.10.10 (NVD, Ubuntu).
The vulnerability stems from an integer overflow issue in 32-bit architectures where the result of sizeof() operations in the eBPF code verifier could lead to incorrect memory allocation. The vulnerability has been assigned a CVSS v3.1 base score of 7.8 (HIGH) with the vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, indicating local access requirements with low attack complexity (NVD, NetApp Advisory).
The vulnerability can allow a local user to crash the system or potentially escalate their privileges. The highest threats from this vulnerability are to system confidentiality, integrity, and availability. Successful exploitation could lead to disclosure of sensitive information, modification of data, or Denial of Service (DoS) (NVD, NetApp Advisory).
The vulnerability requires local access and elevated privileges or non-standard configuration for running BPF scripts. The flaw has been rated as having Moderate impact due to these requirements (Red Hat Bugzilla).
As a temporary mitigation, systems can be protected by setting the sysctl parameter 'kernel.unprivileged_bpf_disabled = 1'. The permanent fix was implemented in Linux kernel version 5.10.10. The fix involves proper handling of integer overflow in argument calculations for bpf_map_area_alloc (Ubuntu, Red Hat Bugzilla).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."