We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2021-22543

Improper memory handling in Linux KVM



Description

An issue was discovered in Linux: KVM through Improper handling of VM_IO|VM_PFNMAP vmas in KVM can bypass RO checks and can lead to pages being freed while still accessible by the VMM and guest. This allows users with the ability to start and control a VM to read/write random pages of memory and can result in local privilege escalation.

Reserved 2021-01-05 | Published 2021-05-26 | Updated 2024-09-16 | Assigner Google


HIGH: 8.7CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L

Problem types

CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

Product status

Default status
unaffected

add6a0cd1c5ba51b201e1361b05a5df817083618 before f8be156be163a052a067306417cd0ff679068c97
affected

Credits

David Stevens finder

Kevin Hamacher finder

Jann Horn finder

References

github.com/...search/security/advisories/GHSA-7wq5-phmq-m584

www.openwall.com/lists/oss-security/2021/06/26/1 ([oss-security] 20210626 Re: CVE-2021-22543 - /dev/kvm LPE) mailing-list

lists.fedoraproject.org/...4G5YBUVEPHZYXMKNGBZ3S6INFCTEEL4E/ (FEDORA-2021-fe826f202e) vendor-advisory

lists.fedoraproject.org/...ROQIXQB7ZAWI3KSGSHR6H5RDUWZI775S/ (FEDORA-2021-95f2f1cfc7) vendor-advisory

security.netapp.com/advisory/ntap-20210708-0002/

lists.debian.org/debian-lts-announce/2021/10/msg00010.html ([debian-lts-announce] 20211015 [SECURITY] [DLA 2785-1] linux-4.19 security update) mailing-list

lists.debian.org/debian-lts-announce/2021/12/msg00012.html ([debian-lts-announce] 20211216 [SECURITY] [DLA 2843-1] linux security update) mailing-list

cve.org (CVE-2021-22543)

nvd.nist.gov (CVE-2021-22543)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2021-22543

Support options

Helpdesk Chat, Email, Knowledgebase