CVE-2021-3489 is a high-severity vulnerability in the Linux kernel's eBPF RINGBUF bpf_ringbuf_reserve() function, affecting versions from 5.8-rc1 up to 5.13-rc4. This flaw allows an attacker to perform out-of-bounds writes due to insufficient size checks, potentially leading to arbitrary code execution within the kernel. With a CVSS score of 7.8, it presents a significant risk, requiring local access but having low attack complexity and high impact on confidentiality, integrity, and availability. There is currently no public exploit code available, nor is there evidence of active exploitation or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.8, < 5.10.37CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.11, < 5.11.21CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.12, < 5.12.4CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
5.13CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:5.13:-:*:*:*:*:*:* | ||
5.13CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:5.13:rc1:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.