The vendor explicitly states that these products are not affected by this CVE.
- kernel as a component of Red Hat Enterprise Linux 6
- kernel-abi-whitelists as a component of Red Hat Enterprise Linux 6
- kernel-bootwrapper as a component of Red Hat Enterprise Linux 6
- kernel-debug as a component of Red Hat Enterprise Linux 6
- kernel-debug-devel as a component of Red Hat Enterprise Linux 6
- kernel-devel as a component of Red Hat Enterprise Linux 6
- kernel-doc as a component of Red Hat Enterprise Linux 6
- kernel-firmware as a component of Red Hat Enterprise Linux 6
- kernel-headers as a component of Red Hat Enterprise Linux 6
- kernel-kdump as a component of Red Hat Enterprise Linux 6
- kernel-kdump-devel as a component of Red Hat Enterprise Linux 6
- kernel.src as a component of Red Hat Enterprise Linux 6
- Summary
- A flaw was found in the Linux kernels eBPF verification code. It was discovered that eBPF ALU32 bounds tracking for bitwise ops (AND, OR and XOR) did not update the 32-bit bounds. By default accessing the eBPF verifier is only accessible to privileged users with CAP_SYS_ADMIN. A local user with the ability to insert eBPF instructions could use this flaw to crash the system or possibly escalate their privileges on the system.
- Remediation
- No remediation text is recorded.
