HIGH · 7.0

CVE-2021-31440

This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel 5.11.15. An attacker must first obtain the ability to execute low-privileged code on the targ...

Vulnerability Description

This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel 5.11.15. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of eBPF programs. The issue results from the lack of proper validation of user-supplied eBPF programs prior to executing them. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the kernel. Was ZDI-CAN-13661.

CVSS Score

7.0

HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
LinuxLinux Kernel>= 5.7, < 5.10.37
NetappSolidfire Baseboard Management Controller Firmware-
NetappSolidfire Baseboard Management Controller-
NetappCloud Backup-
NetappH500S Firmware-
NetappH500S-
NetappH700S Firmware-
NetappH700S-
NetappH300E Firmware-
NetappH300E-
NetappH500E Firmware-
NetappH500E-
NetappH700E Firmware-
NetappH700E-
NetappH410S Firmware-
NetappH410S-
NetappH300S Firmware-
NetappH300S-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-31440?

CVE-2021-31440 is a vulnerability with a CVSS score of 7.0 (HIGH). This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel 5.11.15. An attacker must first obtain the ability to execute low-privileged code on the targ...

How severe is CVE-2021-31440?

CVE-2021-31440 has been rated HIGH with a CVSS base score of 7.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-31440?

Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Netapp Solidfire Baseboard Management Controller Firmware, Netapp Solidfire Baseboard Management Controller, Netapp Cloud Backup, Netapp H500S Firmware.