Vulnerabilities in the eBPF subsystem allow bypassing protection against Spectre-class attacks.
A vulnerability (CVE-2021-33624) has been found in the Linux kernel that allows the eBPF subsystem to bypass protections against Spectre-class vulnerabilities, enabling the determination of memory contents by creating conditions for speculative execution of certain operations. A certain sequence of commands in privileged code is required for a Spectre attack, leading to the speculative execution of instructions. By manipulating the BPF programs passed for execution, it is possible […]
