Database/Kernel, userspace & hypervisor
Linux kernel (eBPF): eBPF improper input validation leading to local privilege escalation
CVSS 7.0CVE-2021-4204Kernel, userspace & hypervisorcurated
Impact
eBPF improper input validation leading to local privilege escalation
Who can reach it
Any tenant process in a container with BPF access
What to do
Livepatchable; otherwise drain + reboot. Set kernel.unprivileged_bpf_disabled=1
References
Related entries
- Linux kernel (cgroups v1): cgroups v1 release_agent lets a container with CAP_SYS_ADMIN (or an unconfined userns) runCVE-2022-0492 · Linux kernel (cgroups v1)High
- Linux kernel (io_uring): Use-after-free between io_uring and the unix GC - local rootCVE-2022-2602 · Linux kernel (io_uring)High
- Linux kernel (OverlayFS/FUSE): OverlayFS copies setuid files from a nosuid FUSE mountCVE-2023-0386 · Linux kernel (OverlayFS/FUSE)High
- Linux kernel (arch/s390/pci): When an SR-IOV VF is hot-unplugged its MMIO resources are freed, but the parent bus keepsCVE-2023-53123 · Linux kernel (arch/s390/pci)High
- Linux kernel (perf): Out-of-bounds write in perf_read_group() via read_size overflow - local rootCVE-2023-6931 · Linux kernel (perf)High
- Linux kernel (IGMP): Use-after-free in IPv4 IGMP - local privilege escalationCVE-2023-6932 · Linux kernel (IGMP)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.