kernel: long jump over an instruction sequence can lead to overflow in the BPF subsystem
Published Dec 8, 2021
7.8
HIGHCVSS 3.1
EPSS 0.52%
Description
The BPF subsystem in the Linux kernel before 4.17 mishandles situations with a long jump over an instruction sequence where inner instructions require substantial expansions into multiple BPF instructions, leading to an overflow. This affects kernel/bpf/core.c and net/core/filter.c.
Affected products
No data.
Configuration 1
- < 4.17
Configuration 2
- n/a
Configuration 3
- n/a
Configuration 4
- n/a
Configuration 5
- n/a
Configuration 6
- n/a
Configuration 7
- n/a
Configuration 8
- n/a
Configuration 9
- n/a
Configuration 10
- n/a
No data.
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-alt
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-alt | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
The default Red Hat Enterprise Linux kernel prevents unprivileged users from being able to use eBPF by the kernel.unprivileged_bpf_disabled sysctl. This would require a privileged user with CAP_SYS_ADMIN or root to be able to abuse this flaw reducing its attack space. For the Red Hat Enterprise Linux 7 the eBPF for unprivileged users is always disabled. For the Red Hat Enterprise Linux 8 to confirm the current state, inspect the sysctl with the command: # cat /proc/sys/kernel/unprivileged_bpf_disabled The setting of 1 would mean that unprivileged users can not use eBPF, mitigating the flaw.
References (9)
- http://packetstormsecurity.com/files/165477/Kernel-Live-Patch-Security-Notice-LSN-0083-1.html x_refsource_MISCThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2018-25020 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2031183 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2018-13801 Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=050fad7c4534c13c8eb1d9c2ba66012e014773cb
- https://github.com/torvalds/linux/commit/050fad7c4534c13c8eb1d9c2ba66012e014773cb x_refsource_MISCPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-25020
- https://security.netapp.com/advisory/ntap-20211229-0005/ x_refsource_CONFIRMThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2018-25020
| Link | Providers | Tags |
|---|---|---|
| http://packetstormsecurity.com/files/165477/Kernel-Live-Patch-Security-Notice-LSN-0083-1.html | x_refsource_MISCThird Party AdvisoryVDB Entry | |
| https://access.redhat.com/security/cve/CVE-2018-25020 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2031183 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2018-13801 | Advisory | |
| https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=050fad7c4534c13c8eb1d9c2ba66012e014773cb | ||
| https://github.com/torvalds/linux/commit/050fad7c4534c13c8eb1d9c2ba66012e014773cb | x_refsource_MISCPatchThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2018-25020 | ||
| https://security.netapp.com/advisory/ntap-20211229-0005/ | x_refsource_CONFIRMThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2018-25020 |
Change history (0)
No recorded changes yet.