Lucene search

K
ubuntucveUbuntu.comUB:CVE-2021-35477
HistoryAug 02, 2021 - 12:00 a.m.

CVE-2021-35477

2021-08-0200:00:00
ubuntu.com
ubuntu.com
52
linux kernel
bpf program
sensitive information
speculative store bypass
side-channel attack

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

16.0%

In the Linux kernel through 5.13.7, an unprivileged BPF program can obtain
sensitive information from kernel memory via a Speculative Store Bypass
side-channel attack because a certain preempting store operation does not
necessarily occur before a store operation that has an attacker-controlled
value.

OSVersionArchitecturePackageVersionFilename
ubuntu20.04noarchlinux< 5.4.0-90.101UNKNOWN
ubuntu21.04noarchlinux< 5.11.0-37.41UNKNOWN
ubuntu20.04noarchlinux-aws< 5.4.0-1059.62UNKNOWN
ubuntu21.04noarchlinux-aws< 5.11.0-1019.20UNKNOWN
ubuntu20.04noarchlinux-aws-5.11< 5.11.0-1019.20~20.04.1UNKNOWN
ubuntu18.04noarchlinux-aws-5.4< 5.4.0-1059.62~18.04.1UNKNOWN
ubuntu20.04noarchlinux-azure< 5.4.0-1063.66UNKNOWN
ubuntu21.04noarchlinux-azure< 5.11.0-1017.18UNKNOWN
ubuntu20.04noarchlinux-azure-5.11< 5.11.0-1017.18~20.04.1UNKNOWN
ubuntu18.04noarchlinux-azure-5.4< 5.4.0-1063.66~18.04.1UNKNOWN
Rows per page:
1-10 of 361

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

16.0%