linux, linux-aws, linux-aws-hwe, linux-azure, linux-azure-4.15, linux-dell300x, linux-gcp, linux-gcp-4.15, linux-hwe, linux-kvm, linux-lts-xenial, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities
It was discovered that the overlayfs implementation in the Linux kernel did not properly validate the application of file system capabilities with respect to user namespaces. A local attacker could use this to gain elevated privileges. (CVE-2021-3493) Piotr Krysiuk discovered that the BPF JIT compiler for x86 in the Linux kernel did not properly validate computation of branch displacements in some situations. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2021-29154)
02 / AFFECTED SOFTWARE
Affected packages
126 explicit affected versions
82 explicit affected versions
42 explicit affected versions
73 explicit affected versions
65 explicit affected versions
88 explicit affected versions
61 explicit affected versions
41 explicit affected versions
95 explicit affected versions
93 explicit affected versions
73 explicit affected versions
62 explicit affected versions
19 explicit affected versions
10 explicit affected versions
18 explicit affected versions
57 explicit affected versions
43 explicit affected versions
60 explicit affected versions
40 explicit affected versions
60 explicit affected versions
50 explicit affected versions
104 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
It was discovered that the overlayfs implementation in the Linux kernel did not properly validate the application of file system capabilities with respect to user namespaces. A local attacker could use this to gain elevated privileges. (CVE-2021-3493) Piotr Krysiuk discovered that the BPF JIT compiler for x86 in the Linux kernel did not properly validate computation of branch displacements in some situations. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2021-29154)
05 / REFERENCES