Vulnerability Description
arch/mips/net/bpf_jit.c in the Linux kernel before 5.4.10 can generate undesirable machine code when transforming unprivileged cBPF programs, allowing execution of arbitrary code within the kernel context. This occurs because conditional branches can exceed the 128 KB limit of the MIPS architecture.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 3.16, < 4.14.251 |
| Netapp | Cloud Backup | - |
| Netapp | H410C Firmware | - |
| Netapp | H410C | - |
| Netapp | H300S Firmware | - |
| Netapp | H300S | - |
| Netapp | H500S Firmware | - |
| Netapp | H500S | - |
| Netapp | H700S Firmware | - |
| Netapp | H700S | - |
| Netapp | H300E Firmware | - |
| Netapp | H300E | - |
| Netapp | H500E Firmware | - |
| Netapp | H500E | - |
| Netapp | H700E Firmware | - |
| Netapp | H700E | - |
| Netapp | H410S Firmware | - |
| Netapp | H410S | - |
| Debian | Debian Linux | 9.0 |
References
- http://www.openwall.com/lists/oss-security/2021/09/15/5Mailing ListPatchThird Party Advisory
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.14.10Mailing ListVendor Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=37ExploitMailing ListPatch
- https://lists.debian.org/debian-lts-announce/2022/03/msg00012.htmlThird Party Advisory
- https://security.netapp.com/advisory/ntap-20211008-0003/Third Party Advisory
- https://www.debian.org/security/2022/dsa-5096Third Party Advisory
- http://www.openwall.com/lists/oss-security/2021/09/15/5Mailing ListPatchThird Party Advisory
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.14.10Mailing ListVendor Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=37ExploitMailing ListPatch
- https://lists.debian.org/debian-lts-announce/2022/03/msg00012.htmlThird Party Advisory
- https://security.netapp.com/advisory/ntap-20211008-0003/Third Party Advisory
- https://www.debian.org/security/2022/dsa-5096Third Party Advisory
FAQ
What is CVE-2021-38300?
CVE-2021-38300 is a vulnerability with a CVSS score of 7.8 (HIGH). arch/mips/net/bpf_jit.c in the Linux kernel before 5.4.10 can generate undesirable machine code when transforming unprivileged cBPF programs, allowing execution of arbitrary code within the kernel con...
How severe is CVE-2021-38300?
CVE-2021-38300 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-38300?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Netapp Cloud Backup, Netapp H410C Firmware, Netapp H410C, Netapp H300S Firmware.