CVE-2021-31440: Demonstrating a Local Privilege Escalation in the Linux Kernel eBPF Verifier

Опубликовано: 27 Май 2021
на канале: Zero Day Initiative
2,660
39

This video demonstrates CVE-2021-31440 - a local privilege escalation vulnerability in the Linux kernel eBPF verifier. Originally reported to the ZDI program by Manfred Paul of the RedRocket CTF team, the bug bypasses the eBPF verification and results in an out-of-bounds (OOB) access in the Linux kernel.

For full details on the bug used in this video, read the blog at:
https://www.zerodayinitiative.com/blo...