We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2021-46974

bpf: Fix masking negation logic upon negative dst register



Description

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix masking negation logic upon negative dst register The negation logic for the case where the off_reg is sitting in the dst register is not correct given then we cannot just invert the add to a sub or vice versa. As a fix, perform the final bitwise and-op unconditionally into AX from the off_reg, then move the pointer from the src to dst and finally use AX as the source for the original pointer arithmetic operation such that the inversion yields a correct result. The single non-AX mov in between is possible given constant blinding is retaining it as it's not an immediate based operation.

Reserved 2024-02-27 | Published 2024-02-27 | Updated 2024-12-19 | Assigner Linux

Product status

Default status
unaffected

ae03b6b1c880a03d4771257336dc3bca156dd51b before 4d542ddb88fb2f39bf7f14caa2902f3e8d06f6ba
affected

f92a819b4cbef8c9527d9797110544b2055a4b96 before 0e2dfdc74a7f4036127356d42ea59388f153f42c
affected

979d63d50c0c0f7bc537bf821e056cc9fe5abd38 before 53e0db429b37a32b8fc706d0d90eb4583ad13848
affected

979d63d50c0c0f7bc537bf821e056cc9fe5abd38 before 2cfa537674cd1051a3b8111536d77d0558f33d5d
affected

979d63d50c0c0f7bc537bf821e056cc9fe5abd38 before 6eba92a4d4be8feb4dc33976abac544fa99d6ecc
affected

979d63d50c0c0f7bc537bf821e056cc9fe5abd38 before 7cf64d8679ca1cb20cf57d6a88bfee79a0922a66
affected

979d63d50c0c0f7bc537bf821e056cc9fe5abd38 before b9b34ddbe2076ade359cd5ce7537d5ed019e9807
affected

Default status
affected

5.0
affected

Any version before 5.0
unaffected

4.14.233
unaffected

4.19.190
unaffected

5.4.117
unaffected

5.10.35
unaffected

5.11.19
unaffected

5.12.2
unaffected

5.13
unaffected

References

git.kernel.org/...c/4d542ddb88fb2f39bf7f14caa2902f3e8d06f6ba

git.kernel.org/...c/0e2dfdc74a7f4036127356d42ea59388f153f42c

git.kernel.org/...c/53e0db429b37a32b8fc706d0d90eb4583ad13848

git.kernel.org/...c/2cfa537674cd1051a3b8111536d77d0558f33d5d

git.kernel.org/...c/6eba92a4d4be8feb4dc33976abac544fa99d6ecc

git.kernel.org/...c/7cf64d8679ca1cb20cf57d6a88bfee79a0922a66

git.kernel.org/...c/b9b34ddbe2076ade359cd5ce7537d5ed019e9807

cve.org (CVE-2021-46974)

nvd.nist.gov (CVE-2021-46974)

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2021-46974

Support options

Helpdesk Chat, Email, Knowledgebase
Telegram Chat
Subscribe to our newsletter to learn more about our work.