Assigner | |
Reserved | 2021-01-05 |
Published | 2021-05-18 |
Updated | 2024-05-15 |
Description
An issue was discovered in Linux: KVM through Improper handling of VM_IO|VM_PFNMAP vmas in KVM can bypass RO checks and can lead to pages being freed while still accessible by the VMM and guest. This allows users with the ability to start and control a VM to read/write random pages of memory and can result in local privilege escalation.
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L |
Problem types
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
Product status
add6a0cd1c5ba51b201e1361b05a5df817083618 before f8be156be163a052a067306417cd0ff679068c97
Credits
David Stevens
Kevin Hamacher
Jann Horn
References
https://github.com/google/security-research/security/advisories/GHSA-7wq5-phmq-m584
http://www.openwall.com/lists/oss-security/2021/06/26/1 ([oss-security] 20210626 Re: CVE-2021-22543 - /dev/kvm LPE)
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4G5YBUVEPHZYXMKNGBZ3S6INFCTEEL4E/ (FEDORA-2021-fe826f202e)
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ROQIXQB7ZAWI3KSGSHR6H5RDUWZI775S/ (FEDORA-2021-95f2f1cfc7)
https://security.netapp.com/advisory/ntap-20210708-0002/
https://lists.debian.org/debian-lts-announce/2021/10/msg00010.html ([debian-lts-announce] 20211015 [SECURITY] [DLA 2785-1] linux-4.19 security update)
https://lists.debian.org/debian-lts-announce/2021/12/msg00012.html ([debian-lts-announce] 20211216 [SECURITY] [DLA 2843-1] linux security update)