Vulnerabilities in the eBPF subsystem that allow code execution at the Linux kernel level
Two new vulnerabilities have been discovered in the eBPF subsystem, allowing handlers to run inside the Linux kernel in a special virtual machine with JIT. Both vulnerabilities enable the execution of custom code with kernel privileges, outside the isolated eBPF virtual machine. Information about the issues was published by the Zero Day Initiative team, which conducts the Pwn2Own competitions, during which three attacks were demonstrated this year […]
