A flaw was found in the Linux kernel. The cBPF JIT compiler may produce machine code with incorrect branches. This flaw allows an unprivileged user to craft anomalous machine code, where the control flow is hijacked to execute arbitrary kernel code. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Platform | Package | Release Date | Advisory |
---|---|---|---|
Amazon Linux 2 - Core | kernel | 2021-10-28 23:22 | ALAS2-2021-1719 |
Amazon Linux 2 - Microvm-kernel-4.14 Extra | microvm-kernel | 2023-09-14 04:27 | ALAS2MICROVM-KERNEL-4.14-2023-001 |
Score Type | Score | Vector | |
---|---|---|---|
Amazon Linux | CVSSv3 | 8.1 | CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H |
NVD | CVSSv2 | 7.2 | AV:L/AC:L/Au:N/C:C/I:C/A:C |
NVD | CVSSv3 | 7.8 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |