CVE-2021-3490 is a vulnerability in the Linux kernel's eBPF subsystem, specifically in the ALU32 bounds tracking for bitwise operations (AND, OR, XOR). The kernel's eBPF verifier failed to properly update 32-bit bounds after these operations, allowing attackers to craft eBPF programs that could perform out-of-bounds reads and writes in kernel memory. This flaw could be exploited to achieve arbitrary code execution in the kernel context. The vulnerable code was introduced in kernel versions 5.7-rc1 (AND/OR) and 5.10-rc1 (XOR).
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
Repository is a C-based local privilege escalation (LPE) proof-of-concept for CVE-2021-3490 in the Linux kernel eBPF verifier. It builds a standalone binary (bin/exploit.bin) that uses crafted eBPF bytecode to obtain out-of-bounds (OOB) access to BPF map value memory, turning it into kernel read/write primitives. The exploit then locates kernel symbols/structures in memory (notably init_pid_ns) and walks kernel PID/task structures to find the current process’s cred pointer, overwrites credential fields to escalate privileges, and finally spawns a shell (system("sh")). Structure/purpose by file: - Makefile: builds exploit.bin with gcc; two build profiles (make groovy / make hirsute) select different hardcoded task_struct offsets via -DGROOVY or -DHIRSUTE. - README.md: reproduction steps on Ubuntu 20.04; explicitly requires enabling unprivileged BPF (kernel.unprivileged_bpf_disabled=0) and installing a specific kernel package set. - bpf.c: thin wrappers around the bpf() syscall (map create/update/lookup, BPF_OBJ_GET_INFO_BY_FD) and a helper to load/attach/run a BPF socket filter program via socketpair + SO_ATTACH_BPF. - include/bpf_defs.h: macros to construct raw eBPF instructions and a custom bpf_map_info struct used for leaking btf_id. - include/exploit_configs.h: exploit context struct and the two-part eBPF “exploit primitive” that triggers the verifier bug (mismatched 32-bit bounds/tnum leading verifier to believe a register is 0 while runtime is 1), enabling pointer arithmetic/OOB. - include/kernel_defs.h: kernel structure offsets and constants; includes Ubuntu-version-specific TASK_LIST_OFFSET and TASK_CRED_OFFSET, plus BPF map field offsets used to pivot from map value memory to bpf_map internals. - kmem_search.c + include/kmem_search.h: implements kernel memory searching and kernel data-structure traversal (radix tree/idr) using the read primitive to resolve init_pid_ns and find the current task’s cred. Exploit capabilities (high level): 1) Creates two BPF array maps (oob_map and store_map). 2) Loads and runs crafted eBPF programs to (a) leak kernel pointers (e.g., map pointer, array_map_ops) and (b) build arbitrary kernel read via BPF_OBJ_GET_INFO_BY_FD leaking btf_id, and arbitrary kernel write via abusing map operations (array_map_get_next_key path). 3) Searches kernel memory for the string/symbol init_pid_ns (kstrtab/ksymtab) starting from array_map_ops, then uses init_pid_ns->idr to resolve pid->task_struct. 4) Reads task_struct to obtain cred pointer and overwrites uid/gid/euid fields to 0. 5) Spawns a root shell. No external C2/network beacons are present; all actions are local and rely on kernel eBPF interfaces and hardcoded offsets for specific Ubuntu kernel builds.
This repository contains a single Metasploit module implementing a local privilege escalation (LPE) exploit for CVE-2021-3490, a vulnerability in the Linux kernel's eBPF ALU32 bounds checking. The exploit targets Linux kernels from 5.7-rc1 up to but not including 5.13-rc4, as well as specific earlier versions (5.12.4, 5.11.21, 5.10.37). The module checks for the presence of a vulnerable kernel, verifies that unprivileged BPF loading is enabled (kernel.unprivileged_bpf_disabled=0), and uploads a custom exploit binary and payload to a writable directory (default: /tmp). Upon successful exploitation, the payload is executed as root, granting the attacker full privileges. The module is operational and leverages Metasploit's payload generation and session management capabilities. No network endpoints are involved; the attack vector is purely local, requiring an existing shell session on the target. The code is written in Ruby and follows standard Metasploit module structure.
This repository contains a local privilege escalation (LPE) exploit for CVE-2021-3490, targeting the Linux kernel's eBPF subsystem. The exploit is written in C and is designed to work on specific Ubuntu kernel versions (20.04.02/20.10 with 5.8.x kernels and 21.04 with 5.11.x kernel). The main entry point is 'exploit.c', which orchestrates the attack by creating eBPF maps, leaking kernel pointers, and ultimately overwriting the current process's credentials in kernel memory to gain root privileges. Supporting files include 'bpf.c' (eBPF helper functions), 'kmem_search.c' (kernel memory search utilities), and several header files defining kernel structures and exploit configuration. The exploit requires eBPF to be enabled on the target system and must be compiled for the correct kernel version. Upon successful exploitation, it spawns a root shell. The Makefile provides build targets for the supported kernel versions. No network endpoints are involved; the attack vector is purely local, leveraging the eBPF syscall interface.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.