kernel/bpf/verifier.c in the Linux kernel before 4.20.6 performs undesirable out-of-bounds speculation on pointer arithmetic in various cases, including cases of different branches with different state or limits to sanitize, leading to side-channel attacks.
| Product | Vendor | Version |
|---|---|---|
| n/a | n/a | < bfd14e5915c2669f292a31d028e75dcd82f1e7e9 |
| n/a | n/a | <= 6.6.* |