vulnerability
Amazon Linux AMI 2: CVE-2021-46974: Security patch for kernel (Multiple Advisories)
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 5 | (AV:L/AC:L/Au:S/C:N/I:N/A:C) | Feb 27, 2024 | May 28, 2024 | May 20, 2026 |
Description
In the Linux kernel, the following vulnerability has been resolved:
bpf: Fix masking negation logic upon negative dst register
The negation logic for the case where the off_reg is sitting in the
dst register is not correct given then we cannot just invert the add
to a sub or vice versa. As a fix, perform the final bitwise and-op
unconditionally into AX from the off_reg, then move the pointer from
the src to dst and finally use AX as the source for the original
pointer arithmetic operation such that the inversion yields a correct
result. The single non-AX mov in between is possible given constant
blinding is retaining it as it's not an immediate based operation.
Solutions
References
- AMAZON-AL2/ALAS-2021-1636
- AMAZON-AL2/ALAS2KERNEL-5.10-2022-001
- AMAZON-AL2/ALAS2KERNEL-5.4-2022-003
- AMAZON-AL2/ALASKERNEL-5.10-2022-001
- AMAZON-AL2/ALASKERNEL-5.4-2022-003
- CVE-2021-46974
- https://attackerkb.com/topics/CVE-2021-46974
- EUVD-EUVD-2021-33622
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-33622
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.