In kernel/bpf/hashtab.c in the Linux kernel through 5.13.8, there is an integer overflow and out-of-bounds write when many elements are placed in a single bucket. NOTE: exploitation might be impractical without the CAP_SYS_ADMIN capability.
| Software | From | Fixed in |
|---|---|---|
| linux / linux_kernel | - | 5.13.8.x |
| fedoraproject / fedora | 33 | 33.x |
| fedoraproject / fedora | 34 | 34.x |
| debian / debian_linux | 11.0 | 11.0.x |