Bug 2036024 (CVE-2021-4159)

Summary: CVE-2021-4159 kernel: another kernel ptr leak vulnerability via BPF in coerce_reg_to_size
Product: [Other] Security Response Reporter: Dhananjay Arunesh <darunesh>
Component: vulnerabilityAssignee: Nobody <nobody>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: acaringi, adscvr, airlied, alciregi, bhu, chwhite, crwood, dvlasenk, hdegoede, hkrzesin, jarod, jarodwilson, jburrell, jeremy, jfaracco, jforbes, jglisse, jlelli, joe.lawrence, jonathan, josef, jross, jshortt, jstancek, jwboyer, kcarcia, kernel-maint, kernel-mgr, lgoncalv, linville, lzampier, masami256, mchehab, nmurray, ptalbert, qzhao, rt-maint, rvrbovsk, scweaver, steved, vkumar, walters, williams, wmealing
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
A vulnerability was found in the Linux kernel's EBPF verifier when handling internal data structures. Internal memory locations could be returned to userspace. A local attacker with the permissions to insert eBPF code to the kernel can use this to leak internal kernel memory details defeating some of the exploit mitigations in place for the kernel.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2040557, 2040558, 2040559, 2041295, 2047752    
Bug Blocks: 2032804    

Description Dhananjay Arunesh 2021-12-29 10:40:20 UTC
A vulnerability was found in Linux kernelS EBPF verifier when handling internal data structures.  Internal memory locations could be returned to userspacec.  A local attacker with the permissions to insert eBPF code to the kernel can use this to leak internal kernel memory details defeating some of the exploit mitigations in place for the kernel.

Comment 8 Guilherme de Almeida Suckevicz 2022-01-28 13:24:56 UTC
Created kernel tracking bugs for this issue:

Affects: fedora-all [bug 2047752]

Comment 9 Justin M. Forbes 2022-01-31 22:50:13 UTC
This was fixed for Fedora with the 5.7.x kernel rebases.