Back to bug 2036024

Who When What Removed Added
Dhananjay Arunesh 2021-12-29 10:40:20 UTC CC security-response-team
Dhananjay Arunesh 2021-12-29 10:42:33 UTC Blocks 2032804
Wade Mealing 2022-01-14 04:30:52 UTC Severity high medium
Priority high medium
Comment 0 updated
Wade Mealing 2022-01-14 04:31:09 UTC CC wmealing
Wade Mealing 2022-01-14 05:01:05 UTC Doc Text A vulnerability was found in Linux kernels EBPF verifier when handling internal data structures. Internal memory locations could be returned to userspacec. A local attacker with the permissions to insert eBPF code to the kernel can use this to leak internal kernel memory details defeating some of the exploit mitigations in place for the kernel.
Wade Mealing 2022-01-14 05:01:56 UTC CC blc, mlangsdo
Wade Mealing 2022-01-14 05:04:02 UTC Depends On 2040557, 2040559, 2040558
Beth Uptagrafft 2022-01-14 15:04:48 UTC Flags needinfo?(wmealing)
Wade Mealing 2022-01-17 00:09:28 UTC Depends On 2041295
Wade Mealing 2022-01-17 00:10:05 UTC Doc Text A vulnerability was found in Linux kernels EBPF verifier when handling internal data structures. Internal memory locations could be returned to userspacec. A local attacker with the permissions to insert eBPF code to the kernel can use this to leak internal kernel memory details defeating some of the exploit mitigations in place for the kernel. A vulnerability was found in Linux kernels EBPF verifier when handling internal data structures. Internal memory locations could be returned to userspace. A local attacker with the permissions to insert eBPF code to the kernel can use this to leak internal kernel memory details defeating some of the exploit mitigations in place for the kernel.
Wade Mealing 2022-01-17 00:16:35 UTC Flags needinfo?(wmealing)
Eric Christensen 2022-01-17 15:19:32 UTC Doc Text A vulnerability was found in Linux kernels EBPF verifier when handling internal data structures. Internal memory locations could be returned to userspace. A local attacker with the permissions to insert eBPF code to the kernel can use this to leak internal kernel memory details defeating some of the exploit mitigations in place for the kernel. A vulnerability was found in the Linux kernel's EBPF verifier when handling internal data structures. Internal memory locations could be returned to userspace. A local attacker with the permissions to insert eBPF code to the kernel can use this to leak internal kernel memory details defeating some of the exploit mitigations in place for the kernel.
Wade Mealing 2022-01-24 00:41:36 UTC CC jolsa
Guilherme de Almeida Suckevicz 2022-01-28 13:24:19 UTC CC adscvr, airlied, alciregi, bskeggs, hdegoede, jarodwilson, jeremy, jglisse, joe.lawrence, jonathan, josef, jwboyer, kernel-maint, kernel-mgr, linville, masami256, mchehab, rt-maint, steved
Summary EMBARGOED CVE-2021-4159 kernel: another kernel ptr leak vulnerability via BPF in coerce_reg_to_size CVE-2021-4159 kernel: another kernel ptr leak vulnerability via BPF in coerce_reg_to_size
Group qe_staff, security
Guilherme de Almeida Suckevicz 2022-01-28 13:24:49 UTC Depends On 2047752
Red Hat Bugzilla 2022-02-28 23:28:45 UTC CC jolsa
Red Hat Bugzilla 2022-04-23 08:29:02 UTC CC esammons
Red Hat Bugzilla 2022-06-04 08:05:14 UTC CC fpacheco
Red Hat Bugzilla 2022-07-16 03:21:27 UTC CC brdeoliv
Red Hat Bugzilla 2022-12-31 23:35:45 UTC CC fhrbata
Red Hat Bugzilla 2023-04-01 08:41:13 UTC CC dhoward
Red Hat Bugzilla 2023-06-14 21:29:52 UTC CC mcressma
Red Hat Bugzilla 2023-07-07 08:30:41 UTC CC security-response-team
Assignee security-response-team nobody

Back to bug 2036024