CVE-2021-46908EPSS p15.2%
CVE-2021-46908CVE-2021-46908
linux / linux_kernel
Description
In the Linux kernel, the following vulnerability has been resolved:
bpf: Use correct permission flag for mixed signed bounds arithmetic
We forbid adding unknown scalars with mixed signed bounds due to the
spectre v1 masking mitigation. Hence this also needs bypass_spec_v1
flag instead of allow_ptr_leaks.
Scoring
| CVSS | 7.1 () |
| Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H |
| EPSS | 0.24% probability of exploitation · percentile 15.2% · 2026-08-05T12:04:55Z |
| Last modified | 2026-08-04 |