APPLIED[H]: [SRU Focal,Groovy,Hirsute,Focal/linux-oem-5.10 0/3] CVE-2021-33200

Kleber Souza kleber.souza at canonical.com
Fri May 28 09:40:13 UTC 2021


On 27.05.21 23:36, Thadeu Lima de Souza Cascardo wrote:
> [Impact]
> The vulnerability allows OOB reads and writes. Code execution cannot be ruled out.
> 
> [Potential regression]
> Some BPF code may be denied to load.
> 
> [Test]
> I tested a reproducer that may cause a kaslr leak, and it was stopped
> after the fixes were applied.
> 
> Daniel Borkmann (3):
>    bpf: Wrap aux data inside bpf_sanitize_info container
>    bpf: Fix mask direction swap upon off reg sign change
>    bpf: No need to simulate speculative domain for immediates
> 
>   kernel/bpf/verifier.c | 46 ++++++++++++++++++++++++++-----------------
>   1 file changed, 28 insertions(+), 18 deletions(-)
> 


Applied to hirsute:linux.

Thanks,
Kleber




More information about the kernel-team mailing list