Another vulnerability in the eBPF subsystem that allows privilege escalation

Another vulnerability has been discovered in the eBPF subsystem (no CVE available), similar to yesterday's issue that allows a local unprivileged user to execute code at the Linux kernel level. The problem has been observed since Linux kernel 5.8 and remains unpatched. A working exploit is expected to be published on January 18.

The new vulnerability is caused by improper validation of eBPF program execution requests. Specifically, the eBPF verifier did not properly restrict certain pointer types *_OR_NULL, allowing pointer manipulation from eBPF programs and enabling privilege escalation. To block exploitation of this vulnerability, it is recommended to disable BPF program execution for unprivileged users with the command 'sysctl -w kernel.unprivileged_bpf_disabled=1'.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster