ALAS-2021-1516 --- kernelID: oval:org.secpod.oval:def:1601454 | Date: (C)2021-07-26 (M)2024-05-22 |
Class: PATCH | Family: unix |
A denial-of-service flaw was identified in the Linux kernel due to an incorrect memory barrier in xt_replace_table in net/netfilter/x_tables.c in the netfilter subsystem. A flaw was found in kernel/bpf/verifier.c in BPF in the Linux kernel. An incorrect limit is enforced for pointer arithmetic operations which can be abused to perform out-of-bounds reads and writes in kernel memory, leading to local privilege escalation. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability
Platform: |
Amazon Linux AMI |