Exploitation Summary
EIP tracks 2 public exploits for CVE-2021-31440. PoCs published by hhhell, WhatsWrongAndWhy.
AI-analyzed exploit summary This repository contains a functional exploit for CVE-2021-31440, a Linux kernel eBPF verifier integer signedness bug that allows local privilege escalation (LPE). The exploit leverages a boundary check bypass in the eBPF verifier to achieve arbitrary kernel memory read/write and ultimately gain root privileges.
Description
This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel 5.11.15. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of eBPF programs. The issue results from the lack of proper validation of user-supplied eBPF programs prior to executing them. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the kernel. Was ZDI-CAN-13661.
Exploits (2)
This repository contains a functional exploit for CVE-2021-31440, a Linux kernel eBPF verifier integer signedness bug that allows local privilege escalation (LPE). The exploit leverages a boundary check bypass in the eBPF verifier to achieve arbitrary kernel memory read/write and ultimately gain root privileges.
The file labeled as 'CVE-2021-31440' is an ELF binary, not human-readable exploit code. The binary contains obfuscated segments, syscalls, and shellcode-like sequences that do not align with the expected technical details of CVE-2021-31440 (a Linux kernel eBPF verifier flaw). The binary appears to be a malicious payload unrelated to the stated CVE.
References (3)
Scores
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H