Home

Description

An issue was discovered in Linux: KVM through Improper handling of VM_IO|VM_PFNMAP vmas in KVM can bypass RO checks and can lead to pages being freed while still accessible by the VMM and guest. This allows users with the ability to start and control a VM to read/write random pages of memory and can result in local privilege escalation.

PUBLISHED Reserved 2021-01-05 | Published 2021-05-26 | Updated 2024-09-16 | Assigner Google




HIGH: 8.7CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L

Problem types

CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

Product status

Default status
unaffected

add6a0cd1c5ba51b201e1361b05a5df817083618 before f8be156be163a052a067306417cd0ff679068c97
affected

Credits

David Stevens finder

Kevin Hamacher finder

Jann Horn finder

References

github.com/...search/security/advisories/GHSA-7wq5-phmq-m584

www.openwall.com/lists/oss-security/2021/06/26/1 ([oss-security] 20210626 Re: CVE-2021-22543 - /dev/kvm LPE) mailing-list

lists.fedoraproject.org/...4G5YBUVEPHZYXMKNGBZ3S6INFCTEEL4E/ (FEDORA-2021-fe826f202e) vendor-advisory

lists.fedoraproject.org/...ROQIXQB7ZAWI3KSGSHR6H5RDUWZI775S/ (FEDORA-2021-95f2f1cfc7) vendor-advisory

security.netapp.com/advisory/ntap-20210708-0002/

lists.debian.org/debian-lts-announce/2021/10/msg00010.html ([debian-lts-announce] 20211015 [SECURITY] [DLA 2785-1] linux-4.19 security update) mailing-list

lists.debian.org/debian-lts-announce/2021/12/msg00012.html ([debian-lts-announce] 20211216 [SECURITY] [DLA 2843-1] linux security update) mailing-list

cve.org (CVE-2021-22543)

nvd.nist.gov (CVE-2021-22543)

Download JSON