{"id":"CVE-2021-20320","title":"A flaw was found in s390 eBPF JIT in bpf_jit_insn in arch/s390/net/bpf_jit_comp.c in the Linux kernel","summary":"A flaw was found in s390 eBPF JIT in bpf_jit_insn in arch/s390/net/bpf_jit_comp.c in the Linux kernel. In this flaw, a local attacker with special user privilege can circumvent the verifier and may lead to a confidentiality problem.","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-200"],"vendor":"linux","product":"linux_kernel","affected":["linux_kernel < 5.15","linux_kernel = 5.15","fedora = 34","enterprise_linux = 7.0","enterprise_linux = 8.0"],"patched":["linux_kernel 5.15"],"published":"2022-02-18","updated":"2026-10-08","sourceUpdated":"2026-10-08T21:17:33.553","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2021-20320","references":[{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2010090","label":"secalert@redhat.com"},{"url":"https://lore.kernel.org/bpf/20210902185229.1840281-1-johan.almbladh%40anyfinetworks.com/","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2010090","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lore.kernel.org/bpf/20210902185229.1840281-1-johan.almbladh%40anyfinetworks.com/","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.0026,"epssPercentile":0.16289,"ingestedAt":"2026-10-08T22:11:53.747Z","slug":"CVE-2021-20320","body":"## Overview\n\nA flaw was found in s390 eBPF JIT in bpf_jit_insn in arch/s390/net/bpf_jit_comp.c in the Linux kernel. In this flaw, a local attacker with special user privilege can circumvent the verifier and may lead to a confidentiality problem.\n\n## Affected\n\n- `linux_kernel < 5.15`\n- `linux_kernel = 5.15`\n- `fedora = 34`\n- `enterprise_linux = 7.0`\n- `enterprise_linux = 8.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `linux_kernel 5.15`","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}