FlawAtlas
Search the atlas
USN-4909-1 Not scored

linux, linux-aws, linux-aws-5.4, linux-azure, linux-azure-5.4, linux-gcp, linux-gcp-5.4, linux-gke-5.4, linux-gkeop, linux-gkeop-5.4, linux-hwe-5.4, linux-kvm, linux-oracle, linux-oracle-5.4, linux-raspi, linux-raspi-5.4 vulnerabilities

Loris Reiff discovered that the BPF implementation in the Linux kernel did not properly validate attributes in the getsockopt BPF hook. A local attacker could possibly use this to cause a denial of service (system crash). (CVE-2021-20194) Olivier Benjamin, Norbert Manthey, Martin Mazein, and Jan H. Schönherr discovered that the Xen paravirtualization backend in the Linux kernel did not properly propagate errors to frontend drivers in some situations. An attacker in a guest VM could possibly use this to cause a denial of service (host domain crash). (CVE-2021-26930) Jan Beulich discovered that multiple Xen backends in the Linux kernel did not properly handle certain error conditions under paravirtualization. An attacker in a guest VM could possibly use this to cause a denial of service (host domain crash). (CVE-2021-26931) It was discovered that the network block device (nbd) driver in the Linux kernel contained a use-after-free vulnerability during device setup. A local attacker with access to the nbd device could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2021-3348)

Exploit probability Not scored
Published April 13, 2021
Required by Not available
Last source change June 3, 2026

02 / AFFECTED SOFTWARE

Affected packages

Ubuntu:18.04:LTS linux-aws-5.4

15 explicit affected versions

Ubuntu:18.04:LTS linux-azure-5.4

14 explicit affected versions

Ubuntu:18.04:LTS linux-gcp-5.4

15 explicit affected versions

Ubuntu:18.04:LTS linux-gke-5.4

10 explicit affected versions

Ubuntu:18.04:LTS linux-gkeop-5.4

10 explicit affected versions

Ubuntu:18.04:LTS linux-hwe-5.4

21 explicit affected versions

Ubuntu:18.04:LTS linux-oracle-5.4

15 explicit affected versions

Ubuntu:18.04:LTS linux-raspi-5.4

14 explicit affected versions

Ubuntu:20.04:LTS linux

33 explicit affected versions

Ubuntu:20.04:LTS linux-aws

27 explicit affected versions

Ubuntu:20.04:LTS linux-azure

24 explicit affected versions

Ubuntu:20.04:LTS linux-gcp

25 explicit affected versions

Ubuntu:20.04:LTS linux-gkeop

5 explicit affected versions

Ubuntu:20.04:LTS linux-kvm

23 explicit affected versions

Ubuntu:20.04:LTS linux-oracle

25 explicit affected versions

Ubuntu:20.04:LTS linux-raspi

18 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities USN-4909-1

Loris Reiff discovered that the BPF implementation in the Linux kernel did not properly validate attributes in the getsockopt BPF hook. A local attacker could possibly use this to cause a denial of service (system crash). (CVE-2021-20194) Olivier Benjamin, Norbert Manthey, Martin Mazein, and Jan H. Schönherr discovered that the Xen paravirtualization backend in the Linux kernel did not properly propagate errors to frontend drivers in some situations. An attacker in a guest VM could possibly use this to cause a denial of service (host domain crash). (CVE-2021-26930) Jan Beulich discovered that multiple Xen backends in the Linux kernel did not properly handle certain error conditions under paravirtualization. An attacker in a guest VM could possibly use this to cause a denial of service (host domain crash). (CVE-2021-26931) It was discovered that the network block device (nbd) driver in the Linux kernel contained a use-after-free vulnerability during device setup. A local attacker with access to the nbd device could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2021-3348)

View original source

05 / REFERENCES

Further evidence