Bug 1972 - [Anolis OS 7] Bugfix for CVE-2021-4159
Summary: [Anolis OS 7] Bugfix for CVE-2021-4159
Status: RESOLVED DUPLICATE of bug 1975
Alias: None
Product: Anolis OS 7
Classification: Anolis OS
Component: BaseOS Packages (show other bugs) BaseOS Packages
Version: 7.7
Hardware: All Linux
: P3-Medium S3-normal
Target Milestone: ---
Assignee: 杨晓旋
QA Contact: 杨晓旋
URL:
Whiteboard:
Keywords: CVE
Depends on:
Blocks:
 
Reported: 2022-08-25 11:10 UTC by 小龙
Modified: 2022-08-25 19:07 UTC (History)
2 users (show)

See Also:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description 小龙 admin 2022-08-25 11:10:22 UTC
A vulnerability was found in the Linux kernel's EBPF verifier when handling internal data structures. Internal memory locations could be returned to userspace. A local attacker with the permissions to insert eBPF code to the kernel can use this to leak internal kernel memory details defeating some of the exploit mitigations in place for the kernel.
Comment 1 zuoyou alibaba_cloud_group 2022-08-25 19:07:33 UTC
deplicate bugzilla(1972 1975)

*** This bug has been marked as a duplicate of bug 1975 ***