/
DirectorySecurity Advisories
Sign In
Security Advisories

CVE-2021-20194

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2021-20194

CGA ID

CGA-w3r7-jh8c-jc5v

Severity

Unknown

Description

There is a vulnerability in the linux kernel versions higher than 5.2 (if kernel compiled with config params CONFIG_BPF_SYSCALL=y , CONFIG_BPF=y , CONFIG_CGROUPS=y , CONFIG_CGROUP_BPF=y , CONFIG_HARDENED_USERCOPY not set, and BPF hook to getsockopt is registered). As result of BPF execution, the local user can trigger bug in __cgroup_bpf_run_filter_getsockopt() function that can lead to heap overflow (because of non-hardened usercopy). The impact of attack could be deny of service or possibly privileges escalation.

References

  • https://images.chainguard.dev/security/CGA-w3r7-jh8c-jc5v

Affected packages


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Products

Chainguard ContainersChainguard LibrariesChainguard VMs