CVE-2021-33624

MEDIUM

Linux kernel <5.12.13 - Memory Corruption

Title source: llm

Description

In kernel/bpf/verifier.c in the Linux kernel before 5.12.13, a branch can be mispredicted (e.g., because of type confusion) and consequently an unprivileged BPF program can read arbitrary memory locations via a side-channel attack, aka CID-9183671af6db.

Exploits (2)

nomisec WORKING POC 3 stars
by benschlueter · poc
https://github.com/benschlueter/CVE-2021-33624
inthewild WORKING POC
poc
https://github.com/kakashiiiiy/cve-2021-33624

Scores

CVSS v3 4.7
EPSS 0.0047
EPSS Percentile 64.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

Classification

CWE
CWE-843
Status published

Affected Products (2)

linux/linux_kernel < 5.12.13
debian/debian_linux

Timeline

Published Jun 23, 2021
Tracked Since Feb 18, 2026