CVE-2021-46908

HIGH

Linux kernel - Mixed Signed Bounds Arithmetic Permission Issue

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: bpf: Use correct permission flag for mixed signed bounds arithmetic We forbid adding unknown scalars with mixed signed bounds due to the spectre v1 masking mitigation. Hence this also needs bypass_spec_v1 flag instead of allow_ptr_leaks.

Scores

CVSS v3 7.1
EPSS 0.0024
EPSS Percentile 15.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (9)
Linux/Linux < 5.8
Linux/Linux 2c78ee898d8f10ae6fb2fa23a3fbaec96b1b7366 - 4ccdc6c6cae38b91c871293fb0ed8c6845a61b51
Linux/Linux 2c78ee898d8f10ae6fb2fa23a3fbaec96b1b7366 - 4f3ff11204eac0ee23acf64deecb3bad7b0db0c6
Linux/Linux 2c78ee898d8f10ae6fb2fa23a3fbaec96b1b7366 - 9601148392520e2e134936e76788fc2a6371e7be
Linux/Linux 5.10.32 - 5.10.*
Linux/Linux 5.11.16 - 5.11.*
Linux/Linux 5.12
Linux/Linux 5.8
linux/linux_kernel 5.8.0 - 5.10.32
Published Feb 27, 2024
Tracked Since Feb 18, 2026